Critical severity9.9NVD Advisory· Published Aug 21, 2026· Updated Aug 21, 2026
CVE-2026-48749
CVE-2026-48749
Description
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixes the issue.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/lxc/incus/v7/cmd/incusdGo | < 7.2.0 | 7.2.0 |
Affected products
2- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.