Description
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 patches the issue.
Published: 2026-08-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Command Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows a specially crafted image or instance backup to read or create and write arbitrary files on the host before version 7.2.0, potentially enabling arbitrary command execution and compromising confidentiality, integrity, and availability. The weakness is classified as CWE-61 and CWE-73.

Affected Systems

Incus, the system container and virtual machine manager developed by LXC, is affected in all releases prior to version 7.2.0. Users running those older versions should upgrade to 7.2.0 or later, which contains a fix that removes the ability to use crafted images or backups to manipulate arbitrary host files.

Risk and Exploitability

The CVSS score of 9.9 indicates a very high severity. The vulnerability can be exploited by submitting a crafted image or backup to the Incus service, which could allow an attacker to read or modify host files and potentially execute commands. EPSS score is < 1%, indicating a very low but nonzero probability of exploitation, and the vulnerability is not listed in KEV. Based on the description, it is inferred that the vulnerability is exploitable by supplying a crafted image or backup to the Incus service, though the exact attack vector (local or remote) is not explicitly stated.

Generated by OpenCVE AI on August 26, 2026 at 13:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Incus version 7.2.0 or later to eliminate the vulnerability.
  • Avoid importing untrusted or unknown container images and backups into the host until the patch is applied.
  • If upgrade is delayed, restrict the host filesystem permissions for the Incus service and monitor for unexpected file creation or modification within the host directories used by Incus.

Generated by OpenCVE AI on August 26, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6370-1 incus security update
Debian DSA Debian DSA DSA-6373-1 lxd security update
Github GHSA Github GHSA GHSA-vxp5-584q-c479 Incus has arbitrary file read+write on host via templates/ symlink in malicious image
History

Wed, 26 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-61
References
Metrics threat_severity

None

threat_severity

Critical


Fri, 21 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Lxc
Lxc incus
Vendors & Products Lxc
Lxc incus

Fri, 21 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 patches the issue.
Title Incus has arbitrary file read+write on host via templates/ symlink in malicious image
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-21T16:40:20.053Z

Reserved: 2026-05-22T19:39:05.355Z

Link: CVE-2026-48752

cve-icon Vulnrichment

Updated: 2026-08-21T16:39:40.508Z

cve-icon NVD

Status : Received

Published: 2026-08-21T15:16:40.667

Modified: 2026-08-21T17:16:31.087

Link: CVE-2026-48752

cve-icon Redhat

Severity : Critical

Publid Date: 2026-08-21T14:31:57Z

Links: CVE-2026-48752 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T13:30:06Z

Weaknesses
  • CWE-61

    UNIX Symbolic Link (Symlink) Following

  • CWE-73

    External Control of File Name or Path