Skip to content
CVSS 9.9 · CRITICAL

CVE-2026-48753Path Traversal RCE in Incus S3 upload endpoint

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.

View on NVD

Analysis

Incus versions prior to 7.1.0 contain a critical vulnerability in the S3 protocol upload endpoint. Attackers can leverage path traversal to create arbitrary files on the host system, which can result in full remote code execution (RCE). Users should upgrade to 7.1.0 immediately.

Relevant roles

ciberseguridadCloudBackendLinuxDocker

Severity

Score: 9.9(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-73

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.

Published: 8/21/2026, 3:16:40 PM
Last modified: 8/21/2026, 4:17:17 PM

References

HomeEventsBlogResourcesCoursesTeam