Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-48755: Incus allows attackers to write arbitrary files on the host
GHSA-v6mj-8pf4-hhw4
CVE-2026-48755
GO-2026-5808
Summary
A vulnerability in Incus's backup compression feature allows attackers to write arbitrary files on the host, potentially leading to unauthorized access. This issue affects Incus's backup compression functionality. To mitigate this risk, update Incus to the latest version or apply a patch if available.
What to do
- Update github.com lxc to version 7.2.0.
- Update lxc github.com/lxc/incus/v7 to version 7.2.0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| go | github.com | lxc |
< 7.2.0 Fix: upgrade to 7.2.0
|
| Go | lxc | github.com/lxc/incus | All versions |
| Go | lxc | github.com/lxc/incus/v6 | All versions |
| Go | lxc | github.com/lxc/incus/v7 |
< 7.2.0 Fix: upgrade to 7.2.0
|
Original title
Incus has an argument injection in backup compression algorithm leading to AFW and ACE in github.com/lxc/incus
Original description
Incus has an argument injection in backup compression algorithm leading to AFW and ACE in github.com/lxc/incus
ghsa CVSS3.1
9.9
Vulnerability type
CWE-20
Improper Input Validation
Published: 7 Jul 2026 · Updated: 7 Jul 2026 · First seen: 26 Jun 2026