VDB

CVE-2026-48751

CVE-2026-48751 PUBLISHED CVSS 9.9 CRITICAL

Reported by GitHub_M · Published August 21, 2026

Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks such as `raw.lxc` and `raw.qemu`. Version 7.2.0 patches the issue.

Risk Scores

CVSS 3.1
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
lxcincus< 7.2.0
alpineincus-feature0, 0, 0
github.comlxc/incus/v7/cmd/incusd0
lxcincus< 7.2.0
alpineincus0, 0, 0

Timeline

  • Jun 26, 2026 CVE Published
  • Jun 27, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 28, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 5, 2026 EPSS Score
  • Sep 6, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›