CVE-2026-33897 - Vulnerability Analysis
CriticalCVSS: 9.9Last Updated: March 26, 2026
Incus - Path Traversal
Published: March 26, 2026Updated: March 26, 2026Remote Exploitable
Overview
Incus < 6.23.0 contains a file read/write vulnerability caused by pongo2 template chroot isolation bypass, letting attackers with instance access read/write files as root on the host, exploit requires instance template usage.
Severity & Score
Severity: Critical
CVSS Score: 9.9
Impact
Attackers can read and write arbitrary files on the host as root, leading to full system compromise.
Mitigation
Update to version 6.23.0 or later.
Related Resources
Details
- CVE ID
- CVE-2026-33897
- Severity
- Critical
- CVSS Score
- 9.9
- Type
- path_traversal
- Status
- new
CWE
- CWE-1336
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H