Skip to content
CVSS 9.9 · CRITICAL

CVE-2026-48755RCE en el host mediante inyección de argumentos en Incus

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution. Version 7.1.0 patches the issue.

Ver en NVD

Análisis

Incus, a system container and VM manager, contains a critical vulnerability in its backup compression logic. This allow attackers to perform argument injection, resulting in arbitrary file writes and potential command execution on the host machine. Users should upgrade to version 7.1.0 immediately.

Roles relevantes

LinuxCloudBackendciberseguridadDocker

Severidad

Puntaje: 9.9(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-20

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution. Version 7.1.0 patches the issue.

Publicada: 21/8/2026, 15:16:41
Última modificación: 21/8/2026, 15:16:41

Referencias

InicioEventosBlogRecursosCursosEquipo