Arbitrary File Access Vulnerability in Incus System Container Manager
CVE-2026-33897
10CRITICAL
What is CVE-2026-33897?
Incus, a container and virtual machine manager, has a vulnerability in its implementation of pongo2 templates which allows arbitrary read or write operations as root on the host system. This security flaw arises from an improper handling of the chroot isolation mechanism, which is supposed to restrict file access to the instance's filesystem. Instead, the pongo2 integration bypasses these protections, granting malicious users direct access to the entire filesystem. As a result, unauthorized access and manipulation of files could lead to significant system security risks. The issue is addressed in version 6.23.0, which is crucial for safeguarding server integrity.
Affected Version(s)
incus < 6.23.0
