Overly permissive cross-domain whitelist in glances - CVE-2026-32610

 

Overly permissive cross-domain whitelist in glances - CVE-2026-32610

Published: March 19, 2026 / Updated: March 19, 2026


Vulnerability identifier: #VU124135
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-32610
CWE-ID: CWE-942
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass the CORS protection mechanism.

The vulnerability exists due to incorrect processing of the "Origin" HTTP header that is supplied within HTTP request. A remote attacker can supply arbitrary value via the "Origin" HTTP header, bypass implemented CORS protection mechanism and steal system monitoring information, configuration secrets and command line arguments.


Affected software

glances

How to mitigate CVE-2026-32610

Install updates from vendor's website.

glances - update to 4.5.2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins