Product
critical
advisory
Incus Path Traversal Vulnerability (CVE-2026-33945)
2 rules 1 TTPA path traversal vulnerability in Incus versions prior to 6.23.0 (CVE-2026-33945) allows an attacker to write arbitrary files as root, leading to privilege escalation and denial of service by crafting a malicious systemd credential path.
Incus
path-traversal
privilege-escalation
denial-of-service
CVE-2026-33945
linux
2r
1t
high
advisory
Incus WebUI Authentication Bypass Vulnerability (CVE-2026-33898)
3 rules 1 TTPIncus versions prior to 6.23.0 are vulnerable to an authentication bypass in the `incus webui` component, allowing local attackers to gain elevated privileges or remote attackers to access system resources by exploiting the incorrect validation of authentication tokens.
Incus
cve-2026-33898
privilege-escalation
authentication-bypass
linux
3r
1t