CVE-2026-33897
Description
A flaw was found in Incus, a system container and virtual machine manager. An attacker with control over instance template files can exploit a vulnerability in the pongo2 templating engine. This flaw allows for arbitrary read or write operations as the root user on the host server by bypassing the intended chroot isolation mechanism. This can lead to unauthorized access and modification of critical system files.
Statement
This Important flaw in Incus, a system container and virtual machine manager, allows an attacker with control over instance template files to bypass chroot isolation. This enables arbitrary file read or write operations as the root user on the host server. This vulnerability affects Incus, which is available as a community project.
Understanding the Weakness (CWE)
Confidentiality
Technical Impact: Read Files or Directories
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.