CVE-2026-48769Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-27); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-27: 1Mentions · 2026-07-01: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-06-27: 1Technical Details · 2026-07-01: 106-2707-01
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-271
Disclosure1
2026-07-011
Patch1
Full discourse2 posts
  • Daily CyberSecurity@the_yellow_fall
    Patch

    Six Incus vulnerabilities, all rated CVSS 9.9, are fixed in v7.2.0. CVE-2026-48769 and CVE-2026-48755 enable root attacks. Update now. #Incus #LinuxContainers #ContainerSecurity #CVE #Cybersecurity #Infosec https://securityonline.info/incus-vulnerabilities-v7-2-0 https://t.co/YzdDqYZTex

    Post summary

    The tweet alerts users that six high‑severity Incus container vulnerabilities (CVEs 2026‑48769 and 2026‑48755) have been fixed in version 7.2.0, urging an update to mitigate root‑level attacks.

    01071661
    12.9K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Incus image download arbitrary file write via crafted Incus-Image-Hash header (CVE-2026-48769) Incus is vulnerable to an arbitrary file write in the http://github.com/lxc/incus/v7/cmd/incusd image download path when handling the Incus-Image-Hash header from remote image servers. The root cause is improper input validation leading to path traversal, allowing a crafted “hash” value to influence filesystem paths before integrity checks complete. An attacker exploits this by operating or tampering with an image server (or MITM’ing image traffic) so Incus pulls an image and processes the malicious header, requiring only that the host is configured to download from the attacker-controlled source. Impact is severe: files can be written outside the intended image directory prior to SHA-256 verification, enabling root-level command execution on the host (e.g., by dropping a cron job). 👉 Affected: http://github.com/lxc/incus/v7/cmd/incusd (versions affected not specified) | No fix yet - treat as suspicious

    Post summary

    CVE-2026-48769 exposes an arbitrary file write via crafted Incus-Image-Hash headers, enabling path traversal and root-level command execution; there is currently no patch or active exploitation reported.

    0000080
    231 followersView on X

Explore more