CVE-2026-48755 affects Incus, a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm parameters allows argument injection in the constructed command line. This vulnerability can lead to arbitrary file writes on the host system. Successful exploitation may further escalate to arbitrary command execution on the host. The issue has been patched in Incus version 7.1.0. Users are advised to upgrade immediately to mitigate the risk. The vulnerability is tracked under GitHub Security Advisory GHSA-v6mj-8pf4-hhw4.