VDB

CVE-2026-48755

CVE-2026-48755 PUBLISHED CVSS 9.9 CRITICAL

Reported by GitHub_M · Published August 21, 2026

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution. Version 7.1.0 patches the issue.

Risk Scores

CVSS 3.1
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
lxcincus< 7.2.0
github.comlxc/incus/v7/cmd/incusd0
alpineincus-feature0, 0, 0
alpineincus0, 0, 0
lxcincus< 7.2.0

Timeline

  • Jun 26, 2026 CVE Published
  • Jun 27, 2026 Security Advisory
  • Aug 21, 2026 CVE Updated
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 6, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›