Critical Vulnerability in Incus: Arbitrary File Write Leads to Root Command Execution
A critical vulnerability (CVE-2026-48769, CVSS 9.9) exists in Incus versions prior to 7.2.0, allowing an attacker to write arbitrary files and execute commands as root on the server. This is triggered by a malicious image server returning a crafted 'Incus-Image-Hash' header. Affected users must update to version 7.2.0 or later immediately.