CVE-2026-68517

Published: Ago 17, 2026 Last Modified: Ago 18, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,5
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: none

Description

AI Translation Available

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list containing the wildcard to retain cors_credentials and expose authenticated REST API data to an untrusted website visited by a previously authenticated user. This issue is fixed in 4.5.6.

942

Permissive Cross-domain Security Policy with Untrusted Domains

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Integrity Availability Access Control
Potential Impacts:
Execute Unauthorized Code Or Commands Bypass Protection Mechanism Read Application Data Varies By Context
Applicable Platforms
Technologies: Web Based, Web Server
View CWE Details
https://github.com/nicolargo/glances/security/advisories/GHSA-fp27-88fp-2phg
https://github.com/nicolargo/glances/commit/890858944ab9d03730ec6b1ba42d4015e6d…
https://github.com/nicolargo/glances/releases/tag/v4.5.6
https://github.com/nicolargo/glances/security/advisories/GHSA-fp27-88fp-2phg