← Back to overview

CVE-2026-48753 affects Incus, a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal attacks. This vulnerability allows attackers to create arbitrary files on the host system. The ability to write arbitrary files can lead to arbitrary command execution on the host. The vulnerability is fixed in Incus version 7.1.0. Users are advised to upgrade to version 7.1.0 or later to remediate the issue. The flaw is documented in both the NVD and a GitHub Security Advisory.

Affected products

  • Incus

Related CVE's

  • CVE-2026-48753

Categories

  • Cloud & Virtualization
  • Zero-Day Vulnerabilities