Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-48769: Incus client can be tricked to write files as root

CVE-2026-48769 · published 13 days ago
Summary

If an Incus server pulls an image from an untrusted source, a malicious image server can send special instructions that cause Incus to create a file anywhere on the host, letting an attacker run commands with full system rights. Update Incus to the latest version and only use trusted image servers, or disable automatic image fetching, to stop this risk.

What to do
  • Update lxc github.com/lxc/incus/v7 to version 7.2.0.
  • Update github.com lxc to version 7.2.0.
  • Update debian incus to version 6.0.4-2+deb13u8.
  • Update debian incus to version 7.0.0-5.
  • Update debian lxd to version 5.0.2+git20231211.1364ae4-9+deb13u7.
Affected software
Ecosystem VendorProductAffected versions
Go lxc github.com/lxc/incus/v7 < 7.2.0
Fix: upgrade to 7.2.0
Ubuntu:Pro:24.04:LTS canonical incus All versions
Ubuntu:20.04:LTS canonical lxd All versions
Ubuntu:Pro:16.04:LTS canonical lxd All versions
Ubuntu:Pro:18.04:LTS canonical lxd All versions
Debian:13 debian incus < 6.0.4-2+deb13u8
Fix: upgrade to 6.0.4-2+deb13u8
Debian:14 debian incus < 7.0.0-5
Fix: upgrade to 7.0.0-5
Debian:12 debian lxd All versions
Debian:13 debian lxd < 5.0.2+git20231211.1364ae4-9+deb13u7
Fix: upgrade to 5.0.2+git20231211.1364ae4-9+deb13u7
go github.com lxc < 7.2.0
Fix: upgrade to 7.2.0
Go lxc github.com/lxc/incus All versions
Go lxc github.com/lxc/incus/v6 All versions
– lxc incus < 7.2.0
Ubuntu:25.10 canonical incus All versions
Ubuntu:Pro:26.04:LTS canonical incus All versions
Original advisory text
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash...
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Version 7.2.0 patches the issue.
Severity
9.9 Critical
CVSS 3.1: 9.9 (GHSA)
CVSS 3.1: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-20Improper Input Validation
Timeline
Published21 Aug 2026
Updated3 Sep 2026
First seen26 Jun 2026
Monitor software like this
Free during beta