CRITICAL
Incus has a restricted project bypass leading to arbitrary command execution
Published Aug 21, 2026
9.9
CRITICALCVSS 3.1
EPSS 0.64%
Description
Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks such as `raw.lxc` and `raw.qemu`. Version 7.2.0 patches the issue.
Affected products
-
- Version < 7.2.0StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
github.com/lxc/incus/v7/cmd/incusd
Go
Introduced 0 Fixed 7.2.0github.com/lxc/incus/v6
Go
Introduced 0 Fixed not fixedgithub.com/lxc/incus/v7
Go
Introduced 0 Fixed 7.2.0github.com/lxc/incus
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/lxc/incus/v7/cmd/incusd | 0 | 7.2.0 |
| Go | github.com/lxc/incus/v6 | 0 | not fixed |
| Go | github.com/lxc/incus/v7 | 0 | 7.2.0 |
| Go | github.com/lxc/incus | 0 | not fixed |
Remediation
Red Hat statement
Incus is not shipped in any Red Hat product. The community Fedora package is affected.
Red Hat mitigation
No mitigation is needed as Incus is not shipped in any Red Hat product.
Weaknesses (2)
References (7)
- https://access.redhat.com/security/cve/CVE-2026-48751 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2521007 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-63978 Advisory
- https://github.com/advisories/GHSA-48q5-w887-33wv Advisory
- https://github.com/lxc/incus/security/advisories/GHSA-48q5-w887-33wv exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-48751
- https://www.cve.org/CVERecord?id=CVE-2026-48751
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-48751 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2521007 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-63978 | Advisory | |
| https://github.com/advisories/GHSA-48q5-w887-33wv | Advisory | |
| https://github.com/lxc/incus/security/advisories/GHSA-48q5-w887-33wv | exploitx_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-48751 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-48751 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 21, 2026
Updated Aug 21, 2026
Reserved May 22, 2026
Link CVE-2026-48751
CISA Vulnrichment
Updated Aug 21, 2026
ENISA EUVD
EUVD-2026-63978 GHSA-48Q5-W887-33WV Assigner GitHub_M
Published Aug 21, 2026
Updated Aug 21, 2026
Exploited since n/a
Link EUVD-2026-63978