CVE-2026-68518Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing adjacent unescaped Mustache variables to reconstruct shell operators that secure_popen() executes when attacker-controlled process or container fields are rendered by an administrator-configured action template. This issue is fixed in 4.5.6.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-17); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-17: 2Mentions · 2026-08-18: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-08-17: 1Technical Details · 2026-08-18: 108-1708-18
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-172
Disclosure1General1
2026-08-181
Patch1
Full discourse3 posts
  • HOL@HashgraphOnline
    Patch

    Glances <=4.5.5: command injection in threshold actions. Action templates get filled with runtime stats like process names, controlled by a local user. Shell operators rebuilt across fields bypass the sanitizer. RCE. Fixed in 4.5.6. CVE-2026-68518 https://hol.org/guard/security/cves/CVE-2026-68518-glances-command-injection-bypass-of-action

    Post summary

    CVE-2026-68518 exposes a local‑user RCE via command injection in Glances 4.5.5 and earlier, but the issue is resolved in 4.5.6.

    5702311.8K
    19.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-68518 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values … https://www.cve.org/CVERecord?id=CVE-2026-68518

    Post summary

    The text describes a vulnerability in Glances before version 4.5.6, specifically naming the sanitization function, but does not mention PoCs, exploits, patches, or active exploitation.

    000011.0K
    58.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-68518 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values … https://www.cve.org/CVERecord?id=CVE-2026-68518 ----- Traducción: CVE-2026-68518 Gla… https://infoflow.cloud`

    Post summary

    The post simply lists CVE‑2026‑68518 for the Glances monitoring tool and notes a function name, but provides no actionable details about exploitation, patching, or severity.

    0000022
    100 followersView on X

Explore more