DNS Rebinding Vulnerability in Glances Monitoring Tool by Glances Team
CVE-2026-46611

5.3MEDIUM

Key Information:

Vendor

Nicolargo

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-46611?

The Glances monitoring tool, an open-source system that facilitates cross-platform monitoring, suffers from a security flaw in its XML-RPC server prior to version 4.5.5. This vulnerability arises due to the lack of validation for the HTTP Host header, allowing attackers to perform DNS rebinding attacks. By exploiting this flaw, an attacker could potentially exfiltrate sensitive system monitoring data from the browser of an unsuspecting victim. The issue has been addressed in version 4.5.5, highlighting the importance of keeping monitoring tools updated to mitigate security threats.

Affected Version(s)

glances < 4.5.5

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.