CVE-2026-48752 affects Incus, a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be leveraged to read or create/write arbitrary files on the host system. This path traversal-style vulnerability could potentially lead to arbitrary command execution on the host. The vulnerability is exploitable via malicious container images or instance backups. Version 7.2.0 has been released to patch the issue. Users are advised to upgrade to version 7.2.0 or later to mitigate the risk. The severity is high given the potential for host-level compromise from within a container context.