HackerFeeds
All CVEs

CVE-2026-48753

CRITICAL9.9

Published 2026-08-21 · Updated 2026-08-21 · Source security-advisories@github.com

Description

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CWE-73
View on NVD