CVE-2026-48752Container-to-host escape in Incus via malicious images
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 patches the issue.
View on NVDAnalysis
Incus (successor to LXD) is vulnerable to a host filesystem escape via crafted images or backups. This allows an attacker to read or write arbitrary files on the host system, potentially leading to full remote code execution on the host.
Relevant roles
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HCWE-73EPSS
No EPSS score yet (CVE may be too fresh).
Technical description
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 patches the issue.