CVE-2026-34839Disclosure(nicolargo / glances)

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch nicolargo glances systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes a REST API (`/api/4/*`) that is accessible without authentication and allows cross-origin requests from any origin due to a permissive CORS policy (`Access-Control-Allow-Origin: *`). This allows a malicious website to read sensitive system information from a running Glances instance in the victim’s browser, leading to cross-origin data exfiltration. While a previous advisory exists for XML-RPC CORS issues, this report demonstrates that the REST API (`/api/4/*`) is also affected and exposes significantly more sensitive data. Version 4.5.4 patches the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-306CWE-942

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • glances

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
glances

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-21: 3Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-21: 304-21
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • DailyCVE@dailycve
    General

    🔴 Glances, Cross-Origin Information Disclosure, #CVE-2026-34839 (High) https://dailycve.com/glances-cross-origin-information-disclosure-cve-2026-34839-high/

    Post summary

    The tweet merely announces CVE-2026-34839, a high‑severity Cross‑Origin Information Disclosure flaw, without providing PoC, exploit, or mitigation details.

    0000024
    183 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34839 Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes a REST API (`/api/4/*`) that is accessible wit… https://www.cve.org/CVERecord?id=CVE-2026-34839

    Post summary

    The text announces that Glances versions prior to 4.5.4 expose a REST API and coupled with the link to the CVE record indicates a disclosure with implied mitigations but no PoC or active exploitation evidence.

    0000068
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34839 Unauthenticated Cross-Origin Data Exfiltration in Glances REST API Before 4.5.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34839

    Post summary

    The snippet announces CVE-2026-34839 as an unauthenticated Cross‑Origin Data Exfiltration vulnerability in Glances REST API versions before 4.5.4, providing basic technical details but no evidence of exploitation or mitigation.

    0000026
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnicolargoglances---

Explore more