CVE-2026-48769Root RCE in Incus via malicious image server
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Version 7.2.0 patches the issue.
View on NVDAnalysis
Incus, el sucesor comunitario de LXD para gestión de contenedores y VMs, presenta una vulnerabilidad de severidad crítica (9.9). Un servidor de imágenes malicioso puede provocar una escritura de archivos arbitrarios que resulta en ejecución de comandos con privilegios de root en el host. Se recomienda actualizar a la versión 7.2.0.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HCWE-20EPSS
No EPSS score yet (CVE may be too fresh).
Technical description
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Version 7.2.0 patches the issue.