CVE-2026-48751 affects Incus, a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots fail to enforce the restricted.containers.lowlevel=block security setting. This bypass allows attackers to abuse low-level hooks such as raw.lxc and raw.qemu to achieve arbitrary command execution on the Incus server. The vulnerability poses a significant risk in multi-tenant or restricted environments where low-level container access is explicitly blocked. Version 7.2.0 resolves the issue with a patch. Users are advised to upgrade immediately to mitigate the risk.