CVE-2026-33945 is a critical path traversal vulnerability affecting Incus, a system container and virtual machine manager, in versions prior to 6.23.0. An authenticated attacker with low privileges can exploit a flaw in how systemd credentials are handled to write to arbitrary files as root outside the intended directory. Rated 9.6 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/I:H/A:H), this vulnerability allows for both privilege escalation and denial of service attacks, though it does not enable data exfiltration. While there is no known public exploit code or evidence of active exploitation, the vulnerability is actively discussed within the cybersecurity community and is on the Hot List. Organizations using Incus should upgrade to version 6.23.0 or later immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.23.0CPE matchmatch criteria | cpe:2.3:a:linuxcontainers:incus:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.