Two high-severity vulnerabilities in Incus exposed users to host compromise through separate attack paths fixed in version 6.23.0. CVE-2026-33897 allows a low-privileged user to abuse pongo2 processing in instance template files to bypass expected chroot-based filesystem isolation and perform arbitrary file reads and writes as root on the host. The issue affects Incus versions prior to 6.23.0 and carries a CVSS v3.1 score reflecting high impact across confidentiality, integrity, and availability.
A second flaw, CVE-2026-33898, affects the temporary local web server launched by incus webui, which improperly accepts an invalid authentication token when that token is passed in the URL. An attacker able to reach that localhost service could obtain the same Incus access as the user who started the interface, creating a path to local privilege escalation or remote abuse if a user is lured into interacting with the web UI. The bug is tracked as CWE-287, while the template-isolation failure is mapped to CWE-1336; both issues were disclosed through GitHub security advisories and resolved in Incus 6.23.0.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Debian published security advisory DSA 6244-1 announcing another security update for Incus. This represents a new downstream Debian package update event separate from the earlier DSA 6212-1 advisory.
Debian published security advisory DSA 6212-1 announcing a security update for Incus. The advisory represents Debian's downstream response to address the previously disclosed Incus vulnerabilities in Debian packages.
A new advisory disclosed CVE-2026-33945, an arbitrary file write vulnerability in Incus versions prior to 6.23.0 caused by improper handling of systemd credential configuration keys in containers. A low-privileged attacker could use path traversal to write files as root outside the intended credentials directory, enabling privilege escalation or denial of service; the issue was fixed in version 6.23.0.
A GitHub security advisory disclosed CVE-2026-33898, a flaw in the temporary local web server started by `incus webui` that incorrectly accepted an invalid authentication token when passed in the URL. The bug could let an attacker reaching the localhost web server gain the same access as the user who launched the UI, and it was fixed in Incus 6.23.0.
A GitHub security advisory disclosed CVE-2026-33897, describing how low-privileged users could abuse pongo2 template functionality to bypass expected chroot isolation and read or write arbitrary files as root on the host. The issue was assigned a high-severity CVSS v3.1 score and mapped to CWE-1336.
Incus released version 6.23.0 to fix two vulnerabilities affecting prior versions: an arbitrary file read/write issue in pongo2-based instance templates and an authentication bypass in the local `incus webui` server.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
6 references tracked. Mallory keeps watching after this page renders.
lists.debian.org
Open sourcelists.debian.org
Open sourcelists.debian.org
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.