Skip to content
CVSS 9.9 · CRITICAL

CVE-2026-48769Root RCE in Incus via malicious image server

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Version 7.2.0 patches the issue.

View on NVD

Analysis

Incus, el sucesor comunitario de LXD para gestión de contenedores y VMs, presenta una vulnerabilidad de severidad crítica (9.9). Un servidor de imágenes malicioso puede provocar una escritura de archivos arbitrarios que resulta en ejecución de comandos con privilegios de root en el host. Se recomienda actualizar a la versión 7.2.0.

Severity

Score: 9.9(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-20

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Version 7.2.0 patches the issue.

Published: 8/21/2026, 3:16:41 PM
Last modified: 8/21/2026, 4:17:17 PM

References

HomeEventsBlogResourcesCoursesTeam