CVE-2026-32610Disclosure(nicolargo / glances)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server ships with a default CORS configuration that sets `allow_origins=["*"]` combined with `allow_credentials=True`. When both of these options are enabled together, Starlette's `CORSMiddleware` reflects the requesting `Origin` header value in the `Access-Control-Allow-Origin` response header instead of returning the literal `*` wildcard. This effectively grants any website the ability to make credentialed cross-origin API requests to the Glances server, enabling cross-site data theft of system monitoring information, configuration secrets, and command line arguments from any user who has an active browser session with a Glances instance. Version 4.5.2 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-942

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • glances

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
glances

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-18: 2Technical Details · 2026-03-18: 203-18
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32610 Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server ships with a default CORS configuration that … https://www.cve.org/CVERecord?id=CVE-2026-32610

    Post summary

    The text discloses a default CORS misconfiguration in Glances prior to v4.5.2 (CVE-2026-32610) without referencing PoC, exploits, or active attacks, and no patch or workaround is mentioned.

    00000109
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32610 - High Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server ships with a default CORS configuration that sets `allow_origins=["*"]... https://www.thehackerwire.com/vulnerability/CVE-2026-32610/ https://t.co/yIP5eK97XF

    Post summary

    The tweet announces a high‑severity CORS misconfiguration in Glances prior to v4.5.2, without providing a PoC, exploit, patch, or evidence of active exploitation.

    0000034
    138 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnicolargoglances---

Explore more