← Terug naar overzicht

CVE-2026-63125 affects Incus, a system container and virtual machine manager, in versions prior to 7.3.0. An unprivileged, project-confined user with can_create_images and can_create_instances permissions can escalate privileges to execute arbitrary code as root on the host. The attack vector involves crafting a malicious image that ships backup.yaml as a symlink pointing to a host file. When the root daemon writes the instance's backup file, it follows the symlink, enabling file write as root and leading to code execution. The vulnerability affects non-admin TLS/RBAC identities, making it accessible to low-privileged users. Version 7.3.0 of Incus patches this issue. Organizations using Incus for container or VM management should upgrade immediately.

Affected products

  • Incus

Related CVE's

  • CVE-2026-63125

Categories

  • Cloud & Virtualization
  • Identity & Access
  • Zero-Day Vulnerabilities