VDB

CVE-2026-48753

CVE-2026-48753 PUBLISHED CVSS 9.9 CRITICAL

Reported by GitHub_M · Published August 21, 2026

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.

Risk Scores

CVSS 3.1
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
lxcincus< 7.1.0
alpineincus-feature0, 0, 0
alpineincus0, 0, 0
github.comlxc/incus/v7/cmd/incusd0
lxcincus< 7.1.0

Timeline

  • May 29, 2026 CVE Published
  • Jun 26, 2026 CVE Updated
  • Jun 27, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 28, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 5, 2026 EPSS Score
  • Sep 6, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›