VDB
CVE-2026-48755
CVE-2026-48755
PUBLISHED
CVSS 9.9 CRITICAL
Reported by GitHub_M · Published August 21, 2026
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution. Version 7.1.0 patches the issue.
Risk Scores
CVSS 3.1
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| lxc | incus | < 7.2.0 |
| github.com | lxc/incus/v7/cmd/incusd | 0 |
| alpine | incus-feature | 0, 0, 0 |
| alpine | incus | 0, 0, 0 |
| lxc | incus | < 7.2.0 |
Timeline
- Jun 26, 2026 CVE Published
- Jun 27, 2026 Security Advisory
- Aug 21, 2026 CVE Updated
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
- Sep 6, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score