CVE-2026-48755: Incus has an argument injection in backup compression algorithm leading to AFW and ACE
Improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-48755 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →