CVE-2026-33897Disclosure(linuxcontainers / incus)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch linuxcontainers incus systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the host server. Incus allows for pongo2 templates within instances which can be used at various times in the instance lifecycle to template files inside of the instance. This particular implementation of pongo2 within Incus allowed for file read/write but with the expectation that the pongo2 chroot feature would isolate all such access to the instance's filesystem. This was allowed such that a template could theoretically read a file and then generate a new version of said file. Unfortunately the chroot isolation mechanism is entirely skipped by pongo2 leading to easy access to the entire system's filesystem with root privileges. Version 6.23.0 patches the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1336

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • incus

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-03-26); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Products
incus

Deep dive

Activity timeline8 mentions / 4d
01223Mentions · 2026-03-26: 3Mentions · 2026-03-27: 3Mentions · 2026-03-28: 1Mentions · 2026-03-29: 1PoC Mentioned / Linked · 2026-03-26: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-03-28: 1Technical Details · 2026-03-26: 3Technical Details · 2026-03-27: 2Technical Details · 2026-03-28: 1Technical Details · 2026-03-29: 103-2603-2703-2803-29
Signal classification3 categories
Disclosure
562.5%
Patch
225.0%
General
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-263
Disclosure2Patch1
2026-03-273
Disclosure1General1Patch1
2026-03-281
Disclosure1
2026-03-291
Disclosure1
Full discourse8 posts
  • maruomosquit@maru1151157
    Disclosure

    🚨 CVE-2026-33897 (CVSS: 9.9) CVE-2026-33897:Incus 6.23.0 以前では、インスタンステンプレートファイルを悪用し、ホストサーバーで任意読み書きが可能。pongo2テンプレートがchroot隔离を回避し、システムファイルへのアクセスが可能。対策は6.23.0のアップデート。 https://maruomosquit.com/vulnerability/CVE-2026-33897/ #脆弱性 #セキュリティ

    Post summary

    CVE-2026-33897 is a critical flaw in Incus allowing attackers to read/write arbitrary host files via instance template exploitation; the issue is mitigated by updating to version 6.23.0.

    0001055
    1.4K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #Incus VM manager contains 6 vulnerabilities including the critical #CVE-2026-33945 and #CVE-2026-33897. Improper access control, path traversal, authentication bypass and other flaws can lead to privilege escalation, #DoS, info disclosure and more. #Patch #Patch #Patch

    Post summary

    The post warns about CVE-2026-33945 and CVE-2026-33897 in the Incus VM manager, detailing access control and path traversal flaws and urging users to apply patches.

    01000265
    7.2K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    CVE-2026-33897 affects `Incus`, enabling arbitrary file read/write via `pongo` templates. This could lead to data exposure or system manipulation. Monitor for patches. #Incus #Security #CVE https://www.pulsepatch.io/posts/cve-2026-33897-incus-arbitrary-file-read-write

    Post summary

    The post announces CVE‑2026‑33897 for Incus, describing an arbitrary file read/write flaw via pongo templates, but provides no PoC, exploit code, or patch details.

    0000035
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33897 Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the… https://www.cve.org/CVERecord?id=CVE-2026-33897

    Post summary

    CVE-2026-33897 reveals that Incus versions prior to 6.23.0 allow arbitrary read or write operations as root via instance template files; no exploit, patch, or active exploitation information is provided.

    00000119
    56.9K followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-33494 | CVSS 10.0 🔴 CVE-2026-33897 | CVSS 9.9 🔴 CVE-2026-33396 | CVSS 9.9 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post simply lists three new CVE identifiers (2026‑33494, 2026‑33897, 2026‑33396) with their CVSS scores and provides a link to the ctiwatch.cloud site, without additional technical or exploitation details.

    0000034
    5.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33897: CRITICAL] Incus allowed arbitrary root access pre-v6.23.0 via template files, impacting system security. Fixed with v6.23.0 patch, preventing unauthorized access.#cve,CVE-2026-33897,#cybersecurity https://cvefind.com/CVE-2026-33897

    Post summary

    The post announces that CVE‑2026‑33897 has been patched in Incus v6.23.0, preventing arbitrary root access via template files.

    0000040
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33897 - Critical Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the host server. Incus a... https://www.thehackerwire.com/vulnerability/CVE-2026-33897/ https://t.co/6Qpm9pbkvH

    Post summary

    The tweet announces CVE-2026-33897 as a critical vulnerability in Incus, highlighting that instance template files allow arbitrary read/write operations with root privileges on hosts running versions prior to 6.23.0.

    0000046
    163 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33897: Incus vulnerable to arbitrary fi... Incus pongo2 templates bypass chroot isolation completely, giving instant root filesystem access from any container - p... https://zerodaysignal.com/vulnerability/CVE-2026-33897 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-33897 reveals that Incus's pongo2 templates can bypass chroot isolation, granting attackers root filesystem access within containers, with a reference link provided but no active exploitation or patch information mentioned.

    0000062
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxcontainersincus---

Explore more