VDB

CVE-2026-48750

CVE-2026-48750 PUBLISHED CVSS 9.9 CRITICAL

Reported by GitHub_M · Published August 21, 2026

Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output` is a symlink, file named `exec_UUID.stdout` and `exec_UUID.stderr` can be written to an arbitrary location where the `.stdout` file will contain arbitrary content. This behavior can be abused for arbitrary command execution. Version 7.2.0 contains a patch.

Risk Scores

CVSS 3.1
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
lxcincus< 7.2.0
alpineincus-feature0, 0, 0
alpineincus0, 0, 0
lxcincus< 7.2.0, < 7.2.0
github.comlxc/incus/v7/cmd/incusd0

Timeline

  • Jun 26, 2026 CVE Published
  • Jun 27, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 28, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 5, 2026 EPSS Score
  • Sep 6, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›