CVE-2026-32608Disclosure(nicolargo / glances)

LOWCVSS 7.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Glances is an open-source system cross-platform monitoring tool. The Glances action system allows administrators to configure shell commands that execute when monitoring thresholds are exceeded. These commands support Mustache template variables (e.g., `{{name}}`, `{{key}}`) that are populated with runtime monitoring data. The `secure_popen()` function, which executes these commands, implements its own pipe, redirect, and chain operator handling by splitting the command string before passing each segment to `subprocess.Popen(shell=False)`. Prior to 4.5.2, when a Mustache-rendered value (such as a process name, filesystem mount point, or container name) contains pipe, redirect, or chain metacharacters, the rendered command is split in unintended ways, allowing an attacker who controls a process name or container name to inject arbitrary commands. Version 4.5.2 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • glances

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-18); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
glances

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-18: 2Mentions · 2026-06-23: 1Technical Details · 2026-03-18: 1Technical Details · 2026-06-23: 103-1806-23
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-182
Disclosure1General1
2026-06-231
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 Glances, Command Injection via AMP Configuration, #CVE-2026-32608 (High) -DC-Jun2026-590 https://dailycve.com/glances-command-injection-via-amp-configuration-cve-2026-32608-high-dc-jun2026-590/

    Post summary

    The shared link announces CVE-2026-32608, a high‑severity command injection flaw in Glances’ AMP configuration, without mentioning exploitation evidence, PoC code, or available mitigation.

    0000038
    216 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32608 Glances is an open-source system cross-platform monitoring tool. The Glances action system allows administrators to configure shell commands that execute when monitor… https://www.cve.org/CVERecord?id=CVE-2026-32608

    Post summary

    The text merely notes the existence of CVE‑2026‑32608 in the Glances monitoring tool with no further details on exploitation, patches, or technical specifics.

    00000163
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32608 Command Injection Vulnerability in Glances System Monitoring Tool... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32608 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    A command injection vulnerability (CVE‑2026‑32608) has been disclosed for the Glances system monitoring tool, with details posted on Vulmon, but no PoC, exploit, or mitigation information is provided.

    0000042
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnicolargoglances---

Explore more