Skip to content
CVSS 9.9 · CRITICAL

CVE-2026-48769RCE como root en Incus mediante servidor de imágenes malicioso

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Version 7.2.0 patches the issue.

Ver en NVD

Análisis

Incus, el sucesor comunitario de LXD para gestión de contenedores y VMs, presenta una vulnerabilidad de severidad crítica (9.9). Un servidor de imágenes malicioso puede provocar una escritura de archivos arbitrarios que resulta en ejecución de comandos con privilegios de root en el host. Se recomienda actualizar a la versión 7.2.0.

Severidad

Puntaje: 9.9(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-20

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Version 7.2.0 patches the issue.

Publicada: 21/8/2026, 15:16:41
Última modificación: 21/8/2026, 16:17:17

Referencias

InicioEventosBlogRecursosCursosEquipo