CVE Explorer
CVE-2026-33711
Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the screenshot to which is then picked up and sent to the user prior to deletion. As versions prior to 6.23.0 use predictable paths under /tmp for this, an attacker with local access to the system can abuse this mechanism by creating their own symlinks ahead of time. On the vast majority of Linux systems, this will result in a
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"incus","vendor":"lxc","versions":[{"status":"affected","version":"< 6.23.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6c6266438cae31332f130501652628be019625257d379438466df318f1bb69f5 · sha256:5465f14a9f7db76e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"LOCAL","baseScore":4.7,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6c6266438cae31332f130501652628be019625257d379438466df318f1bb69f5 · sha256:5465f14a9f7db76e… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-61","description":"CWE-61: UNIX Symbolic Link (Symlink) Following","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6c6266438cae31332f130501652628be019625257d379438466df318f1bb69f5 · sha256:5465f14a9f7db76e… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["exploit"],"url":"https://github.com/lxc/incus/security/advisories/GHSA-q9vp-3wcg-8p4x"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6c6266438cae31332f130501652628be019625257d379438466df318f1bb69f5 · sha256:5465f14a9f7db76e… · /containers/adp/0/references/0
{"name":"https://github.com/lxc/incus/security/advisories/GHSA-q9vp-3wcg-8p4x","tags":["x_refsource_CONFIRM"],"url":"https://github.com/lxc/incus/security/advisories/GHSA-q9vp-3wcg-8p4x"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6c6266438cae31332f130501652628be019625257d379438466df318f1bb69f5 · sha256:5465f14a9f7db76e… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.