CORS Vulnerability in Glances Monitoring Tool by Glances Team
CVE-2026-68517

6.5MEDIUM

Key Information:

Vendor

Nicolargo

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-68517?

The Glances monitoring tool prior to version 4.5.6 has a CORS vulnerability due to the cors_origins guard using exact list equality instead of wildcard membership. This flaw allows an untrusted website, previously accessed by an authenticated user, to potentially expose sensitive REST API data. The issue is rectified in version 4.5.6, thereby enhancing the security of the tool against cross-origin requests.

Affected Version(s)

glances < 4.5.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.