PatchSiren cyber security CVE debrief
CVE-2026-48749 lxc CVE debrief
Incus, a system container and virtual machine manager, has a critical vulnerability (CVE-2026-48749) that allows a specially crafted image to read or create/write arbitrary files on the host, possibly leading to arbitrary command execution. This issue is fixed in version 7.2.0. Users and administrators should be aware of this vulnerability and take immediate action to protect their systems. The vulnerability has a CVSS score of 9.9 and is considered critical.
- Vendor
- lxc
- Product
- incus
- CVSS
- CRITICAL 9.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-21
Who should care
Users and administrators of Incus, a system container and virtual machine manager, should be aware of this critical vulnerability and take immediate action to protect their systems. This includes assessing Incus installations for potential exposure, applying version 7.2.0 or later, monitoring for suspicious activity related to Incus image processing, and implementing compensating controls to restrict access to Incus. Additionally, security teams and vulnerability management teams should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Operators and platform administrators should also review compensating controls for exposed systems while remediation is scheduled and verified, and track exceptions, retest remediated assets, and close the item only after evidence is documented. The vulnerability's criticality and potential impact on confidentiality, integrity, and availability necessitate prompt attention and action from all relevant stakeholders, including developers, security teams, and IT management, to ensure the security and integrity of their systems and data processed by Incus. The vulnerability affects Incus versions prior to 7.2.0, and users should verify their system versions and update accordingly. The CVSS score of 9.9 indicates a critical vulnerability that can be easily exploited and has a high impact on the system, making it essential for users to prioritize patching and mitigation efforts. The vulnerability is publicly known and has been reported by multiple sources, emphasizing the need for immediate action to prevent potential attacks. The recommended actions include inventory and assessment of Incus installations, application of version 7.2.0 or later, monitoring for suspicious activity, and implementation of compensating controls. The vulnerability's severity and potential impact underscore the importance of prompt action and coordination among stakeholders to mitigate the risk effectively. The CVE record and official advisory provide critical information on the vulnerability, its CVSS
Technical summary
A specially crafted image can be used to read or create/write arbitrary files on the host in Incus, possibly leading to arbitrary command execution. This issue is fixed in version 7.2.0. The vulnerability has a CVSS score of 9.9 and is considered critical. Incus users and administrators should assess their installations for potential exposure and apply version 7.2.0 or later to address the vulnerability.
Defensive priority
Critical vulnerability in Incus, a system container and virtual machine manager, allowing arbitrary file access and possible command execution.
Recommended defensive actions
- Inventory and assess Incus installations for potential exposure
- Apply version 7.2.0 or later to address the vulnerability
- Monitor for suspicious activity related to Incus image processing
- Implement compensating controls to restrict access to Incus
- Review the official advisory and CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record indicates a critical vulnerability in Incus, with a CVSS score of 9.9. A specially crafted image can be used to read or create/write arbitrary files on the host, possibly leading to arbitrary command execution. Version 7.2.0 fixes the issue.
Official resources
-
CVE-2026-48749 CVE record
CVE.org
-
CVE-2026-48749 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:40.247Z and has not been modified since then.