Origin validation error in glances - CVE-2026-46611
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to origin validation error in glances/server.py in GlancesXMLRPCHandler and GlancesXMLRPCServer when handling XML-RPC requests with an unvalidated Host header during DNS rebinding. A remote attacker can lure a victim into visiting an attacker-controlled web page and trigger crafted requests to disclose sensitive information.
User interaction is required, and exploitation depends on the victim's browser being able to reach the XML-RPC server.