CVE-2026-48750 – Incus

CVSS 9.9 CRITICAL Zero Day – Immediate Deployment

“Multiple paths around Incus security boundaries can expose host files, elevate privileges, and reach root-level execution.”

Incus fixes a broad set of security flaws involving unsafe file handling, symlink attacks, argument injection, missing authorization checks, and project-restriction bypasses. The issues can expose sensitive instance or volume data, allow arbitrary host file access or writes, bypass container restrictions, and in several cases lead to arbitrary command execution or host compromise. Fixes are included across Incus 7.1.0, 7.2.0, and 7.3.0.

CVE-2026-48749 has a CVSS score of 9.9, Critical severity. CVE-2026-48750 has a CVSS score of 9.9, Critical severity. CVE-2026-48751 has a CVSS score of 9.9, Critical severity. CVE-2026-48752 has a CVSS score of 9.9, Critical severity. CVE-2026-48753 has a CVSS score of 9.9, Critical severity. CVE-2026-48755 has a CVSS score of 9.9, Critical severity. CVE-2026-48769 has a CVSS score of 9.9, Critical severity. CVE-2026-62867 has a CVSS score of 9.9, Critical severity. CVE-2026-62940 has a CVSS score of 9.9, Critical severity. CVE-2026-62941 has a CVSS score of 9.9, Critical severity. CVE-2026-63125 has a CVSS score of 9.9, Critical severity. CVE-2026-63343 has a CVSS score of 9.9, Critical severity. CVE-2026-55621 has a CVSS score of 7.7, High severity. CVE-2026-55622 has a CVSS score of 7.7, High severity.

Public proof-of-concept exploitation is confirmed for CVE-2026-48749, CVE-2026-48751, CVE-2026-48753, CVE-2026-48769, CVE-2026-62941, CVE-2026-63125, and CVE-2026-55622.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-73
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.