Privilege Escalation Vulnerability in Incus by LXD
CVE-2026-33945

10CRITICAL

Key Information:

Vendor

Lxc

Status
Vendor
CVE Published:
26 March 2026

What is CVE-2026-33945?

Incus, a system container and virtual machine manager, allows configurations to be passed to systemd within guest instances. Prior to version 6.23.0, a vulnerability existed where attackers could manipulate a configuration key to write outside the intended 'credentials' directory, potentially leading to unauthorized file writing as root. While direct data reading is not possible through this exploit, the ability to write arbitrary files raises significant concerns for both privilege escalation and denial of service attacks. Version 6.23.0 addresses and mitigates this vulnerability.

Affected Version(s)

incus < 6.23.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.