CVE-2026-48753Path Traversal RCE in Incus S3 upload endpoint
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.
View on NVDAnalysis
Incus versions prior to 7.1.0 contain a critical vulnerability in the S3 protocol upload endpoint. Attackers can leverage path traversal to create arbitrary files on the host system, which can result in full remote code execution (RCE). Users should upgrade to 7.1.0 immediately.
Relevant roles
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HCWE-73EPSS
No EPSS score yet (CVE may be too fresh).
Technical description
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.