Junglewise Threat Intelligence

CVE-2026-48751: Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlev

CVE-2026-48751 · Severity: critical · CVSS 9.9 · Published 2026-08-21

Technologies: github.com/lxc/incus/v7/cmd/incusd (Go), github.com/lxc/incus/v6 (Go), github.com/lxc/incus (Go), github.com/lxc/incus/v7 (Go). Vendors: Go.

Executive brief

Incus, a container and virtual machine management tool, contains a security flaw where restricted project settings are ignored during the restoration of instance snapshots. This allows a user with limited access to bypass security boundaries and execute commands with administrative (root) privileges on the host server. An attacker could use this to take full control of the server, access sensitive data, or disrupt operations.

Technical details

A vulnerability in Incus allows for a restricted project bypass leading to arbitrary command execution. The root cause is that instance snapshots fail to honor the 'restricted.containers.lowlevel=block' configuration setting. An attacker with low privileges can craft a malicious instance with low-level hooks (such as raw.lxc or raw.qemu) in an unrestricted environment, create a snapshot, and then move and restore that snapshot within a restricted project. Upon starting the restored instance, the low-level hooks execute on the host with root privileges. This issue is addressed in Incus version 7.2.0.

Affected products

  • LXC Incus < 7.2.0

Timeline

  • 2026-06-25: disclosed
  • 2026-06-26: advisory
  • 2026-06-26: patched: Fixed in version 7.2.0

References

Related threats