maruomosquit[verified]@maru1151157Disclosure
CVE-2026-33897 is a critical flaw in Incus allowing attackers to read/write arbitrary host files via instance template exploitation; the issue is mitigated by updating to version 6.23.0.
CCB Alert@CCBalertPatch
The post warns about CVE-2026-33945 and CVE-2026-33897 in the Incus VM manager, detailing access control and path traversal flaws and urging users to apply patches.
PulsePatch.io@pulsepatchioDisclosure
The post announces CVE‑2026‑33897 for Incus, describing an arbitrary file read/write flaw via pongo templates, but provides no PoC, exploit code, or patch details.
CVE@CVEnewDisclosure
CVE-2026-33897 reveals that Incus versions prior to 6.23.0 allow arbitrary read or write operations as root via instance template files; no exploit, patch, or active exploitation information is provided.
CTIWatch@ctiwatchcloudGeneral
The post simply lists three new CVE identifiers (2026‑33494, 2026‑33897, 2026‑33396) with their CVSS scores and provides a link to the ctiwatch.cloud site, without additional technical or exploitation details.
CVEFind.com@CveFindComPatch
The post announces that CVE‑2026‑33897 has been patched in Incus v6.23.0, preventing arbitrary root access via template files.
The Hacker Wire@TheHackerWireDisclosure
The tweet announces CVE-2026-33897 as a critical vulnerability in Incus, highlighting that instance template files allow arbitrary read/write operations with root privileges on hosts running versions prior to 6.23.0.
0day Signal@0dayPublishingDisclosure
CVE-2026-33897 reveals that Incus's pongo2 templates can bypass chroot isolation, granting attackers root filesystem access within containers, with a reference link provided but no active exploitation or patch information mentioned.