Cross-Site Resource Sharing Issue in Glances Monitoring Tool
CVE-2026-46608

7.4HIGH

Key Information:

Vendor

Nicolargo

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-46608?

The Glances monitoring tool features a CORS misconfiguration that allows unauthorized cross-origin requests. An operator attempting to create an explicit allowlist may inadvertently expose their system's monitoring data. Specifically, when two origins are listed, Glances defaults to allowing all origins instead. This flaw enables any malicious webpage to make requests to the Glances XML-RPC server, potentially compromising sensitive system data. This vulnerability has been addressed in version 4.5.5.

Affected Version(s)

glances < 4.5.5

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.