CVE-2026-48749 affects Incus, a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be leveraged to read or create/write arbitrary files on the host system. This path traversal or similar image-handling flaw could potentially lead to arbitrary command execution on the host. The vulnerability is critical as it allows container escape scenarios. The fix was introduced in Incus version 7.2.0. Users are strongly advised to upgrade immediately. The issue was disclosed via GitHub Security Advisories under GHSA-2q3f-q5pq-g8wv.