CVE-2026-33945Disclosure(linuxcontainers / incus)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linuxcontainers incus systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. Prior to version 6.23.0, an attacker can set a configuration key named something like `systemd.credential.../../../../../../root/.bashrc` to cause Incus to write outside of the `credentials` directory associated with the container. This makes use of the fact that the Incus syntax for such credentials is `systemd.credential.XYZ` where `XYZ` can itself contain more periods. While it's not possible to read any data this way, it's possible to write to arbitrary files as root, enabling both privilege escalation and denial of service attacks. Version 6.23.0 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • incus

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 5 mentions (2026-03-27); latest day: 1
  • 9 total mentions across 4 days

Affected systems

Products
incus

Deep dive

Activity timeline9 mentions / 4d
01345Mentions · 2026-03-26: 2Mentions · 2026-03-27: 5Mentions · 2026-03-28: 1Mentions · 2026-06-26: 1Patch / Workaround · 2026-03-27: 2Patch / Workaround · 2026-03-28: 1Technical Details · 2026-03-26: 2Technical Details · 2026-03-27: 3Technical Details · 2026-03-28: 1Technical Details · 2026-06-26: 103-2603-2703-2806-26
Signal classification3 categories
Disclosure
777.8%
General
111.1%
Patch
111.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-262
Disclosure2
2026-03-275
Disclosure3General1Patch1
2026-03-281
Disclosure1
2026-06-261
Disclosure1
Full discourse9 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: #Incus VM manager contains 6 vulnerabilities including the critical #CVE-2026-33945 and #CVE-2026-33897. Improper access control, path traversal, authentication bypass and other flaws can lead to privilege escalation, #DoS, info disclosure and more. #Patch #Patch #Patch

    Post summary

    Incus VM Manager is warned to contain six critical vulnerabilities, including CVE‑2026‑33945 and CVE‑2026‑33897, involving improper access control, path traversal, and authentication bypass that could lead to privilege escalation, DoS, and information disclosure.

    01000265
    7.2K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Incus, Path Traversal in Image Import leading to Arbitrary File Write, #CVE-2026-33945 (Critical) -DC-Jun2026-686 https://dailycve.com/incus-path-traversal-in-image-import-leading-to-arbitrary-file-write-cve-2026-33945-critical-dc-jun2026-686/

    Post summary

    Incus is affected by a critical path‑traversal vulnerability in image import that can be exploited to write arbitrary files, as announced by dailycve.

    0000031
    216 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An arbitrary file write (CVE-2026-33945) affects `Incus` via `systemd-creds` options. This could lead to system compromise. Monitor vendor guidance for patches. #Incus #ContainerSecurity #Infosec https://www.pulsepatch.io/posts/cve-2026-33945-incus-arbitrary-file-write

    Post summary

    CVE-2026-33945 is an arbitrary file write vulnerability affecting Incus via systemd‑creds options; no PoC or active exploitation is reported, but users should watch for vendor patches.

    0000028
    6 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33945 Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handle… https://www.cve.org/CVERecord?id=CVE-2026-33945

    Post summary

    The snippet names CVE‑2026‑33945 and notes a credential‑handling issue in Incus, but provides no actionable details about exploitation, mitigation, or evidence of real‑world attacks.

    00000116
    56.9K followersView on X
  • maruomosquit@maru1151157
    Patch

    🚨 CVE-2026-33945 (CVSS: 9.9) Incus 6.23.0以前では、設定キーにパス透過を活用し、rootとして任意ファイルに書き込み可能となり、権限昇格やサービス停止が可能。バージョン6.23.0で修正。 https://maruomosquit.com/vulnerability/CVE-2026-33945/ #脆弱性 #セキュリティ

    Post summary

    The tweet announces CVE‑2026‑33945, a high‑severity privilege‑escalation flaw in Incus versions before 6.23.0 that was patched in 6.23.0, with a link to a vulnerability page for additional details.

    0000053
    1.4K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-33945 📊 Severity: 9.9 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33945 #CVE-2026-33945 #CVE #Critical #CyberSecurity #InfoSec https://t.co/vmGu5LCx40

    Post summary

    A tweet announces CVE‑2026‑33945 with a high severity rating but offers no technical details, PoC, or remediation guidance.

    0000036
    123 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33945 - Critical Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared di... https://www.thehackerwire.com/vulnerability/CVE-2026-33945/ https://t.co/scMq9F2Mbr

    Post summary

    The post announces CVE-2026-33945, noting that Incus can expose credentials to systemd in guest containers; technical details are provided but no PoC, exploit, patch, or active exploitation is mentioned.

    0000064
    163 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-33945: CRITICAL] Incus, a system container manager, was vulnerable to a privilege escalation issue before version 6.23.0. Attackers could exploit this flaw to write to arbitrary files as root. Upda...#cve,CVE-2026-33945,#cybersecurity https://cvefind.com/CVE-2026-33945

    Post summary

    The text announces a critical privilege‑escalation flaw (CVE‑2026‑33945) in Incus that allows attackers to write arbitrary files as root on versions older than 6.23.0, without providing PoC, exploit, patch, or active exploitation evidence.

    0000042
    617 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33945: Abitrary file write through syst... Path traversal in Incus systemd credential keys lets attackers write arbitrary files as root—perfect for container esca... https://zerodaysignal.com/vulnerability/CVE-2026-33945 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-33945, a path‑traversal flaw in Incus systemd credential keys that enables arbitrary root file writes and can facilitate container escape.

    0000073
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxcontainersincus---

Explore more