← Terug naar overzicht

A critical vulnerability exists in Incus, a system container and virtual machine manager, prior to version 7.2.0. The vulnerability resides in the `record-output` parameter of the `/instances/$name/exec` API endpoint. When the `exec-output` directory is a symlink, output files (exec_UUID.stdout and exec_UUID.stderr) can be written to arbitrary filesystem locations. The `.stdout` file can contain arbitrary content controlled by an attacker. This symlink following behavior can be chained to achieve arbitrary command execution on the host system. The vulnerability has been patched in Incus version 7.2.0, which users are advised to upgrade to immediately.

Affected products

  • Incus

Related CVE's

  • CVE-2026-48750

Categories

  • Cloud & Virtualization
  • Zero-Day Vulnerabilities