← Terug naar overzicht

CVE-2026-48769 affects Incus, a system container and virtual machine manager. Prior to version 7.2.0, a vulnerability exists in the Incus client that allows arbitrary file writes when a malicious image server returns a crafted 'Incus-Image-Hash' header. This arbitrary file write can be escalated to arbitrary command execution with root privileges on the server. The vulnerability is exploitable via a man-in-the-middle or rogue image server scenario. The issue has been patched in Incus version 7.2.0. Users are strongly advised to upgrade to version 7.2.0 or later to mitigate the risk. No workarounds are currently documented aside from upgrading.

Affected products

  • Incus

Related CVE's

  • CVE-2026-48769

Categories

  • Cloud & Virtualization
  • Zero-Day Vulnerabilities