VDB
CVE-2026-48753
CVE-2026-48753
PUBLISHED
CVSS 9.9 CRITICAL
Reported by GitHub_M · Published August 21, 2026
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.
Risk Scores
CVSS 3.1
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| lxc | incus | < 7.1.0 |
| alpine | incus-feature | 0, 0, 0 |
| alpine | incus | 0, 0, 0 |
| github.com | lxc/incus/v7/cmd/incusd | 0 |
| lxc | incus | < 7.1.0 |
Timeline
- May 29, 2026 CVE Published
- Jun 26, 2026 CVE Updated
- Jun 27, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
- Sep 5, 2026 EPSS Score
- Sep 6, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score