PT-2026-53014 · Incus+1 · Incus+1

CVE-2026-48755

·

Published

2026-06-26

·

Updated

2026-09-01

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Incus versions prior to 7.1.0
Description Improper validation of the user-provided backup compression algorithm allows for argument injection in the constructed command line. The system validates the compression algorithm by checking only the first token against an allowlist, failing to reject additional arguments. This flaw allows an attacker to use the compressFile() function to perform an arbitrary file write on the host, which can potentially lead to arbitrary command execution. This can be achieved by passing a crafted string to the compression algorithm variable, such as using zstd with the -o flag to specify a destination file on the host system.
Recommendations Update Incus to version 7.1.0.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48755
GHSA-V6MJ-8PF4-HHW4
GO-2026-5808
OPENSUSE-SU-2026:11651-1
OPENSUSE-SU-2026:21483-1

Affected Products

Incus
Red Os