Back

CRITICAL

Incus has a restricted project bypass leading to arbitrary command execution

Published Aug 21, 2026

Description

Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks such as `raw.lxc` and `raw.qemu`. Version 7.2.0 patches the issue.

Affected products

Remediation

Red Hat statement

Incus is not shipped in any Red Hat product. The community Fedora package is affected.

Red Hat mitigation

No mitigation is needed as Incus is not shipped in any Red Hat product.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 21, 2026
Updated Aug 21, 2026
Reserved May 22, 2026
CISA Vulnrichment
Updated Aug 21, 2026
NVD
Status Deferred
Modified Sep 18, 2026
Red Hat
Severity Critical
Public date Aug 21, 2026
ENISA EUVD
Assigner GitHub_M
Published Aug 21, 2026
Updated Aug 21, 2026
Exploited since n/a
EUVD-2026-63978 GHSA-48Q5-W887-33WV