All CVEs View on NVD
CVE-2026-48753
CRITICAL9.9
Published 2026-08-21 · Updated 2026-08-21 · Source security-advisories@github.com
Description
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-73

