PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-48753 lxc CVE debrief

The Incus system container and virtual machine manager, prior to version 7.1.0, contains a critical vulnerability in its S3 protocol upload endpoint. This vulnerability allows for path traversal, enabling the creation of arbitrary files on the host system. Such exploitation could lead to arbitrary command execution, posing a significant risk to users of affected versions. The issue is addressed in version 7.1.0, where the vulnerability is fixed. Users are advised to upgrade to this version or later to mitigate the risk. Additionally, restricting access to the S3 protocol upload endpoint and closely monitoring the host system for suspicious activity are recommended as defensive measures. Evidence supporting this vulnerability is derived from CVE and NVD details, emphasizing the need for verification of Incus versions and implementation of restrictive access controls.

Vendor
lxc
Product
incus
CVSS
CRITICAL 9.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-21
Advisory published
2026-08-21
Advisory updated
2026-08-21

Who should care

Users of Incus system container and virtual machine manager, particularly those using versions prior to 7.1.0, should be aware of this critical vulnerability. Operators, platform administrators, vulnerability management teams, and security teams should review the vulnerability details and plan for mitigation. Upgrading to version 7.1.0 or later is recommended. Restricting access to the S3 protocol upload endpoint and monitoring for suspicious activity on the host system are also advised. This vulnerability could lead to arbitrary command execution, making it a high priority for affected users to address.

Technical summary

The S3 protocol upload endpoint in Incus versions prior to 7.1.0 is vulnerable to path traversal, allowing creation of arbitrary files on the host, which could lead to arbitrary command execution. This vulnerability impacts Incus system container and virtual machine manager users, particularly those using versions prior to 7.1.0. The issue is fixed in version 7.1.0. Users should upgrade to the latest version and restrict access to the S3 protocol upload endpoint.

Defensive priority

Critical vulnerability in Incus system container and virtual machine manager, allowing arbitrary file creation and command execution.

Recommended defensive actions

  • Upgrade to Incus version 7.1.0 or later
  • Restrict access to the S3 protocol upload endpoint
  • Monitor for suspicious activity on the host system
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The S3 protocol upload endpoint in Incus versions prior to 7.1.0 is vulnerable to path traversal, allowing creation of arbitrary files on the host, which could lead to arbitrary command execution. Version 7.1.0 fixes the issue. Evidence is limited to CVE and NVD details. Defenders should verify Incus version and restrict access to the S3 protocol upload endpoint. Additional review of host system logs and monitoring for suspicious activity is recommended.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:40.800Z and has not been modified since then.