Critical severity9.9NVD Advisory· Published Aug 21, 2026· Updated Sep 18, 2026
CVE-2026-48750
CVE-2026-48750
Description
Incus is a system container and virtual machine manager. Prior to version 7.2.0, the record-output parameter of the /instances/$name/exec endpoint stores the output of the command in the exec-output directory of the instance. If exec-output is a symlink, file named exec_UUID.stdout and exec_UUID.stderr can be written to an arbitrary location where the .stdout file will contain arbitrary content. This behavior can be abused for arbitrary command execution. Version 7.2.0 contains a patch.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/lxc/incus/v7/cmd/incusdGo | < 7.2.0 | 7.2.0 |
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/incus&distro=openSUSE%20Tumbleweed
< 0.0.20260723T184607-160000.1.1+ 1 more
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
- (no CPE)range: < 7.4-1.1
Patches
Vulnerability mechanics
References
2News mentions
1- Incus: 18 Vulnerabilities Disclosed, Nine Critical, Allowing Root AccessVypr Intelligence · Aug 21, 2026