Loading market data...
← Back to CVE feed

CVE-2026-48753

CRITICAL CVSS 9.9 View on NVD ↗

Description

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Published: Aug 21, 2026 15:16 UTC Modified: Aug 21, 2026 16:17 UTC