Arbitrary File Write Vulnerability in Incus System Container Management Software
CVE-2026-48769
9.9CRITICAL
What is CVE-2026-48769?
Incus, a system container and virtual machine manager, contains an arbitrary file write vulnerability in its client application. This security flaw occurs when a malicious image server returns a specially crafted Incus-Image-Hash header. Exploiting this vulnerability allows attackers to write arbitrary files on the server, which can lead to unauthorized command execution with root privileges. The issue was resolved in version 7.2.0, which effectively patches the vulnerability.
Affected Version(s)
incus < 7.2.0
