PT-2026-53014 · Incus+1 · Incus+1
CVE-2026-48755
·
Published
2026-06-26
·
Updated
2026-09-01
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Incus versions prior to 7.1.0
Description
Improper validation of the user-provided backup compression algorithm allows for argument injection in the constructed command line. The system validates the
compression algorithm by checking only the first token against an allowlist, failing to reject additional arguments. This flaw allows an attacker to use the compressFile() function to perform an arbitrary file write on the host, which can potentially lead to arbitrary command execution. This can be achieved by passing a crafted string to the compression algorithm variable, such as using zstd with the -o flag to specify a destination file on the host system.Recommendations
Update Incus to version 7.1.0.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Incus
Red Os