/Vulnerability Library

Glances - Information Disclosure

CVE-2026-32596
Verified

Description

Glances < 4.5.2 contains an information disclosure vulnerability caused by the web server running without authentication by default, letting remote attackers access sensitive system information including credentials, exploit requires no special privileges.

Severity

High

CVSS Score

7.5

Exploit Probability

2%

Published Date

March 19, 2026

Template Author

theamanrawat

CVE-2026-32596.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-32596
CWE ID:
cwe-200

References

https://github.com/nicolargo/glances/security/advisories/GHSA-wvxv-4j8q-4wjqhttps://nvd.nist.gov/vuln/detail/CVE-2026-32596

Remediation Steps

Update to version 4.5.2 or later.