
Glances <=4.5.5: command injection in threshold actions. Action templates get filled with runtime stats like process names, controlled by a local user. Shell operators rebuilt across fields bypass the sanitizer. RCE. Fixed in 4.5.6. CVE-2026-68518 https://hol.org/guard/security/cves/CVE-2026-68518-glances-command-injection-bypass-of-action
Post summary
CVE-2026-68518 exposes a local‑user RCE via command injection in Glances 4.5.5 and earlier, but the issue is resolved in 4.5.6.


