SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-48753

CRITICAL · CVSS 9.9 EPSS 0.71% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The S3 protocol upload endpoint in Incus versions prior to 7.1.0 is vulnerable to path traversal, enabling attackers to create arbitrary files on the host system. This flaw could lead to arbitrary command execution, posing a critical risk to system integrity and security. Organizations using affected versions of Incus should prioritize upgrading to version 7.1.0 or later to mitigate this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-48753
Severity
CRITICAL
CVSS
9.9
EPSS
0.71%

Original NVD Description

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.