CVE-2026-48755
CRITICAL9.9CVSS v3
—CVSS v2
0.44%
EPSS (exploit probability)
CWE-20CWE
Description
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution. Version 7.1.0 patches the issue.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected routers (0)
No routers currently mapped to this CVE in our database.