CVE-2026-48751
Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the restricted.containers.lowlevel=block setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks such as raw.lxc and raw.qemu. Version 7.2.0 patches the issue.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48751.json, https://github.com/lxc/incus/security/advisories/GHSA-48q5-w887-33wv, https://nvd.nist.gov/vuln/detail/CVE-2026-48751