PT-2026-28575 · Incus+1 · Incus+1

Grmpyninja

+1

·

Published

2026-01-01

·

Updated

2026-04-20

·

CVE-2026-33945

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Incus versions prior to 6.23.0
Description Incus is a system container and virtual machine manager. Incus instances allow providing credentials to systemd within the guest environment, managed through a shared directory for containers. Prior to version 6.23.0, an attacker could manipulate a configuration key, such as systemd.credential.../../../../../../root/.bashrc, to induce Incus to write files outside the designated credentials directory. This is possible because the Incus syntax for credentials, systemd.credential.XYZ, permits multiple periods within the XYZ component. While reading data is not possible through this method, writing to arbitrary files as root is achievable, potentially leading to privilege escalation and denial of service attacks. The vulnerability leverages the ability to traverse directory structures using specially crafted credential names.
Recommendations Versions prior to 6.23.0 should be updated to version 6.23.0 or later.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07367
CVE-2026-33945
GHSA-Q4Q8-7F2J-9H9F
GO-2026-4884
OPENSUSE-SU-2026:10450-1

Affected Products

Incus
Red Os