Skip to content
CVSS 9.9 · CRITICAL

CVE-2026-48753RCE por salto de directorio en el endpoint S3 de Incus

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.

Ver en NVD

Análisis

Incus versions prior to 7.1.0 contain a critical vulnerability in the S3 protocol upload endpoint. Attackers can leverage path traversal to create arbitrary files on the host system, which can result in full remote code execution (RCE). Users should upgrade to 7.1.0 immediately.

Roles relevantes

ciberseguridadCloudBackendLinuxDocker

Severidad

Puntaje: 9.9(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-73

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.

Publicada: 21/8/2026, 15:16:40
Última modificación: 21/8/2026, 15:16:40

Referencias

InicioEventosBlogRecursosCursosEquipo