Lxc Incus vulnerabilities
37 known vulnerabilities affecting lxc/incus.
Total CVEs
37
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH8MEDIUM13LOW2
Vulnerabilities
Page 1 of 2
CVE-2026-33897P2CRITICALCVSS 9.9fixed in 6.23.02026-03-26
CVE-2026-33897 [CRITICAL] CWE-1336 CVE-2026-33897: Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template
Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the host server. Incus allows for pongo2 templates within instances which can be used at various times in the instance lifecycle to template files inside of the instance. This particular
nvdosv
CVE-2026-48769P2CRITICALCVSS 9.9fixed in 7.2.02026-08-21
CVE-2026-48769 [CRITICAL] CWE-20 CVE-2026-48769: Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file w
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Version 7.2.0 patches the issue.
nvd
CVE-2026-48752P2CRITICALCVSS 9.9fixed in 7.2.02026-08-21
CVE-2026-48752 [CRITICAL] CWE-73 CVE-2026-48752: Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 patches the issue.
nvd
CVE-2026-48749P2CRITICALCVSS 9.9fixed in 7.2.02026-08-21
CVE-2026-48749 [CRITICAL] CWE-73 CVE-2026-48749: Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixes the issue.
nvd
CVE-2026-48753P2CRITICALCVSS 9.9fixed in 7.1.02026-08-21
CVE-2026-48753 [CRITICAL] CWE-73 CVE-2026-48753: Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upl
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.
nvd
CVE-2026-48755P2CRITICALCVSS 9.9fixed in 7.2.02026-08-21
CVE-2026-48755 [CRITICAL] CWE-20 CVE-2026-48755: Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution. Version 7.1.0 patches the issue.
nvd
CVE-2026-63125P2CRITICALCVSS 9.9fixed in 7.3.02026-08-21
CVE-2026-63125 [CRITICAL] CWE-59 CVE-2026-63125: Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, pr
Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on the host. A crafted image ships `backup.yaml` as a symlink to a host file. When the root daemon writes
nvd
CVE-2026-62867P2CRITICALCVSS 9.9fixed in 7.3.02026-08-21
CVE-2026-62867 [CRITICAL] CWE-88 CVE-2026-62867: Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation
Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command line. This allows a project-scoped user to inject arbitrary arguments into the binary executed as root
nvd
CVE-2026-48750P2CRITICALCVSS 9.9fixed in 7.2.02026-08-21
CVE-2026-48750 [CRITICAL] CWE-73 CVE-2026-48750: Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output`
Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output` is a symlink, file named `exec_UUID.stdout` and `exec_UUID.stderr` can be written to an arbitrary loc
nvd
CVE-2026-48751P2CRITICALCVSS 9.9fixed in 7.2.02026-08-21
CVE-2026-48751 [CRITICAL] CWE-862 CVE-2026-48751: Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots
Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks such as `raw.lxc` and `raw.qemu`. Version 7.2.0 patches the issue.
nvd
CVE-2026-63343P2CRITICALCVSS 9.9fixed in 7.3.02026-08-21
CVE-2026-63343 [CRITICAL] CWE-73 CVE-2026-63343: Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image c
Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host as root via the instance metadata API. The `exec-output` and `templates/` paths were patched in a prio
nvd
CVE-2026-62941P2CRITICALCVSS 9.9fixed in 7.3.02026-08-21
CVE-2026-62941 [CRITICAL] CWE-863 CVE-2026-62941: Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an ins
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the request. Dangerous configuration keys (including `security.privileged`, `raw.lxc`, `raw.apparmor`) from
nvd
CVE-2026-33945P2CRITICALCVSS 9.6fixed in 6.23.02026-03-27
CVE-2026-33945 [CRITICAL] CWE-22 CVE-2026-33945: Incus is a system container and virtual machine manager. Incus instances have an option to provide c
Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. Prior to version 6.23.0, an attacker can set a configuration key named something like `systemd.credential.../../../../../../root/.bashrc` to cause Incus t
nvdosv
CVE-2026-62940P2CRITICALCVSS 9.9fixed in 7.3.02026-08-21
CVE-2026-62940 [CRITICAL] CWE-862 CVE-2026-62940: Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an i
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like `security.privileged` and `raw.lxc`) are applied without any project restriction enforcement, allowing a restricted project user to escal
nvd
CVE-2026-23954P3HIGHCVSS 8.7v>= 6.1.0, <= 6.20.0≤ 6.0.52026-01-22
CVE-2026-23954 [HIGH] CWE-22 CVE-2026-23954: Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with
Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write. This ultimately re
nvdosv
CVE-2026-23953P3HIGHCVSS 8.7v>= 6.1.0, <= 6.20.0≤ 6.0.52026-01-22
CVE-2026-23953 [HIGH] CWE-93 CVE-2026-23953: Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with t
Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ group) can create an environment variable containing newlines, which can be used to add additional configuration items in the container’s lxc.conf due to newli
nvdosv
CVE-2026-33898P3HIGHCVSS 8.8fixed in 6.23.02026-03-27
CVE-2026-33898 [HIGH] CWE-287 CVE-2026-33898: Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spa
Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value will be accepted. `incus webui` runs a local web server on a random localhost port. For authentication, it provides the user with a URL containing an authent
nvd
CVE-2026-55621P3HIGHCVSS 7.7fixed in 7.2.02026-08-21
CVE-2026-55621 [HIGH] CWE-284 CVE-2026-55621: Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorizati
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of a custom volume in that project can copy the custom volume to a new project. This issue could allow an attacker to a
nvd
CVE-2026-55622P3HIGHCVSS 7.7fixed in 7.2.02026-08-21
CVE-2026-55622 [HIGH] CWE-284 CVE-2026-55622: Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorizati
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets
nvd
CVE-2026-33711P3HIGHCVSS 7.8fixed in 6.23.02026-03-26
CVE-2026-33711 [HIGH] CWE-61 CVE-2026-33711: Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screen
Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the screenshot to which is then picked up and sent to the user prior to deletion. As versions prior to 6.23.0 use predictable paths under /tmp for this, an attacker with local access
nvdosv
1 / 2Next →