CVE-2026-23954Disclosure(linuxcontainers / incus)

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch linuxcontainers incus systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write. This ultimately results in arbitrary command execution on the host. When using an image with a metadata.yaml containing templates, both the source and target paths are not checked for symbolic links or directory traversal. This can also be exploited in IncusOS. A fix is planned for versions 6.0.6 and 6.21.0, but they have not been released at the time of publication.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • incus

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-06-26)
  • 3 total mentions across 2 days

Affected systems

Products
incus

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-20: 1Mentions · 2026-06-26: 2Patch / Workaround · 2026-04-20: 1Technical Details · 2026-06-26: 204-2006-26
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-201
Patch1
2026-06-262
Disclosure2
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 Incus, Path Traversal & Symlink Vulnerability, #CVE-2026-23954 (Critical) -DC-Jun2026-678 https://dailycve.com/incus-path-traversal-symlink-vulnerability-cve-2026-23954-critical-dc-jun2026-678/

    Post summary

    The text announces a new critical CVE-2026-23954 involving a path traversal and symlink vulnerability in Incus, without providing PoC, exploit, patch, or active exploitation details.

    0000040
    216 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 LXD, Path Traversal via Symlink, #CVE-2026-23954 (Critical) -DC-Jun2026-679 https://dailycve.com/lxd-path-traversal-via-symlink-cve-2026-23954-critical-dc-jun2026-679/

    Post summary

    The post announces CVE‑2026‑23954, a critical path‑traversal vulnerability in LXD that exploits symlinks, but it offers no proof of concept, exploitation details, or mitigation information.

    0000050
    216 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Fedora ships Incus 6.23 security update for Fedora 42 and 43, fixing CVE-2025-58183, CVE-2026-23954, CVE-2025-69725 and CVE-2026-23953 in the container hypervisor. https://threatcluster.io/cluster/fedora-incus-623-security-update-addresses-multiple-vulnerab-faf3dc82

    Post summary

    Fedora released an update to Incus 6.23 that fixes four CVEs in its container hypervisor, but the post does not provide technical details or evidence of exploitation.

    00000300
    160 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxcontainersincus---

Explore more