← Back to CVE search

CVE-2026-48753

Incus

Description

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.

CVSS 9.9EPSS 0.709%Risk 1.05
View source
Published
2026-08-21 15:16:40
Affected versions
<7.1.0
Type
Other
Last modified
2026-08-21 16:17:17
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H