Arbitrary File Access Vulnerability in Incus System Container Manager
CVE-2026-33897

10CRITICAL

Key Information:

Vendor

Lxc

Status
Vendor
CVE Published:
26 March 2026

What is CVE-2026-33897?

Incus, a container and virtual machine manager, has a vulnerability in its implementation of pongo2 templates which allows arbitrary read or write operations as root on the host system. This security flaw arises from an improper handling of the chroot isolation mechanism, which is supposed to restrict file access to the instance's filesystem. Instead, the pongo2 integration bypasses these protections, granting malicious users direct access to the entire filesystem. As a result, unauthorized access and manipulation of files could lead to significant system security risks. The issue is addressed in version 6.23.0, which is crucial for safeguarding server integrity.

Affected Version(s)

incus < 6.23.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.