CVE-2026-48749

9.9

LXC · Incus

Incus versions prior to 7.2.0 are vulnerable to arbitrary file read, write, or creation via crafted images, potentially leading to arbitrary command execution on the host system.

Executive summary

A critical vulnerability in the Incus system container manager allows authenticated users to achieve arbitrary command execution on the host via crafted images.

Vulnerability

This vulnerability involves improper external control of file paths (CWE-73), allowing a low-privileged authenticated user to manipulate host files through malicious container images.

Business impact

Successful exploitation grants an attacker the ability to read sensitive host data or write files to the host filesystem, which can be leveraged to gain full control over the underlying server. Given the CVSS score of 9.9, this represents a critical risk to infrastructure integrity, potentially leading to total system compromise and data exfiltration.

Remediation

Immediate Action: Update the Incus software to version 7.2.0 or later to apply the necessary security patch.

Proactive Monitoring: Monitor system logs for unauthorized file access attempts or suspicious container image deployments.

Compensating Controls: Restrict the ability to import or manage container images to trusted administrative personnel only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a severe risk to containerized environments and requires immediate attention. Security teams should prioritize patching Incus to version 7.2.0 across all instances to prevent potential host-level exploitation.

More LXC CVEs