Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-48753

CRITICAL NVD
CVSS Score 9.9
Severity CRITICAL
Published Aug 21, 2026
Vendor unknown

Description

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.

References