CVE-2026-33533Disclosure(nicolargo / glances)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch nicolargo glances systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (activated with glances -s or glances --server) sends Access-Control-Allow-Origin: * on every HTTP response. Because the XML-RPC handler does not validate the Content-Type header, an attacker-controlled webpage can issue a CORS "simple request" (POST with Content-Type: text/plain) containing a valid XML-RPC payload. The browser sends the request without a preflight check, the server processes the XML body and returns the full system monitoring dataset, and the wildcard CORS header lets the attacker's JavaScript read the response. The result is complete exfiltration of hostname, OS version, IP addresses, CPU/memory/disk/network stats, and the full process list including command lines (which often contain tokens, passwords, or internal paths). This issue has been patched in version 4.5.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-942

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • glances

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-06-22)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
glances

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-02: 1Mentions · 2026-04-07: 1Mentions · 2026-06-22: 2Patch / Workaround · 2026-04-02: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-07: 1Technical Details · 2026-06-22: 204-0204-0706-22
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-021
Disclosure1
2026-04-071
Disclosure1
2026-06-222
Disclosure1General1
Full discourse4 posts
  • DailyCVE@dailycve
    General

    🔴 Glances (XML-RPC Server), CORS Misconfiguration / Mitigation Bypass, #CVE-2026-33533 (High) -DC-Jun2026-558 https://dailycve.com/glances-xml-rpc-server-cors-misconfiguration-mitigation-bypass-cve-2026-33533-high-dc-jun2026-558/

    Post summary

    The post announces CVE‑2026‑33533, a CORS misconfiguration in the Glances XML‑RPC Server, but does not provide PoC, exploit, or patch details.

    0000034
    216 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Glances XML-RPC Server, DNS Rebinding via Host Header Validation Bypass (#CVE-2026-33533 / #CVE-2026-32632) – High -DC-Jun2026-561 https://dailycve.com/glances-xml-rpc-server-dns-rebinding-via-host-header-validation-bypass-cve-2026-33533-cve-2026-32632-high-dc-jun2026-561/

    Post summary

    The post announces two high‑severity CVEs affecting the Glances XML‑RPC Server, describing a DNS rebinding via host header validation bypass. No PoC, exploit code, active exploitation, or patch details are provided.

    0000043
    216 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `Glances` is vulnerable to cross-origin system information disclosure via its XML-RPC server CORS wildcard (CVE-2026-33533). Restrict network access to mitigate. #infosec #security #Glances https://www.pulsepatch.io/posts/cve-2026-33533-glances-system-information-disclosure

    Post summary

    The post announces CVE‑2026‑33533, describing a cross‑origin information disclosure flaw in Glances’ XML‑RPC server and advises restricting network access as a mitigation.

    0000043
    11 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33533 Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (activated with glances -s or glances --server) se… https://www.cve.org/CVERecord?id=CVE-2026-33533

    Post summary

    The text is a brief disclosure of CVE-2026-33533, noting that the Glances XML-RPC server is vulnerable before version 4.5.3 and referencing the official CVE record.

    0000060
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnicolargoglances---

Explore more