Path Traversal Vulnerability in Incus System Container and Virtual Machine Manager
CVE-2026-48753
9.9CRITICAL
What is CVE-2026-48753?
Incus, a system container and virtual machine management tool, contains a vulnerability in the S3 protocol upload endpoint that enables path traversal. This flaw permits an attacker to create arbitrary files on the host system, posing a serious risk of arbitrary command execution. Users are encouraged to update to version 7.1.0 or later to mitigate this issue.
Affected Version(s)
incus < 7.1.0
