CVE-2026-32634

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised server name and the discovered IP address for dynamic servers, but later builds connection URIs from the untrusted advertised name instead of the discovered IP. When a dynamic server reports itself as protected, Glances also uses that same untrusted name as the lookup key for saved passwords and the global `[passwords] default` credential. An attacker on the same local network can advertise a fake Glances service over Zeroconf and cause the browser to automatically send a reusable Glances authentication secret to an attacker-controlled host. This affects the background polling path and the REST/WebUI click-through path in Central Browser mode. Version 4.5.2 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nicolargo:glances:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:36

Type Values Removed Values Added
Summary
  • (es) Glances es una herramienta de monitoreo de sistema de código abierto multiplataforma. Antes de la versión 4.5.2, en modo Navegador Central, Glances almacena tanto el nombre del servidor anunciado por Zeroconf como la dirección IP descubierta para servidores dinámicos, pero luego construye URIs de conexión a partir del nombre anunciado no confiable en lugar de la IP descubierta. Cuando un servidor dinámico se reporta como protegido, Glances también usa ese mismo nombre no confiable como clave de búsqueda para contraseñas guardadas y la credencial global '[passwords] default'. Un atacante en la misma red local puede anunciar un servicio Glances falso a través de Zeroconf y hacer que el navegador envíe automáticamente un secreto de autenticación de Glances reutilizable a un host controlado por el atacante. Esto afecta la ruta de sondeo en segundo plano y la ruta de clic de REST/WebUI en modo Navegador Central. La versión 4.5.2 corrige el problema.

19 Mar 2026, 19:03

Type Values Removed Values Added
First Time Nicolargo glances
Nicolargo
References () https://github.com/nicolargo/glances/commit/61d38eec521703e41e4933d18d5a5ef6f854abd5 - () https://github.com/nicolargo/glances/commit/61d38eec521703e41e4933d18d5a5ef6f854abd5 - Patch
References () https://github.com/nicolargo/glances/releases/tag/v4.5.2 - () https://github.com/nicolargo/glances/releases/tag/v4.5.2 - Release Notes
References () https://github.com/nicolargo/glances/security/advisories/GHSA-vx5f-957p-qpvm - () https://github.com/nicolargo/glances/security/advisories/GHSA-vx5f-957p-qpvm - Exploit, Vendor Advisory
CPE cpe:2.3:a:nicolargo:glances:*:*:*:*:*:*:*:*

18 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-18 18:16

Updated : 2026-06-17 10:36


NVD link : CVE-2026-32634

Mitre link : CVE-2026-32634

CVE.ORG link : CVE-2026-32634


JSON object : View

Products Affected

nicolargo

  • glances
CWE
CWE-346

Origin Validation Error

CWE-522

Insufficiently Protected Credentials