Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-21 15:16
Updated : 2026-08-21 16:17
NVD link : CVE-2026-48753
Mitre link : CVE-2026-48753
CVE.ORG link : CVE-2026-48753
JSON object : View
Products Affected
No product.
CWE
CWE-73
External Control of File Name or Path
