OS Command Injection in glances - CVE-2026-68518

 

OS Command Injection in glances - CVE-2026-68518

Published: August 3, 2026


Vulnerability identifier: #VU140771
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-68518
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary commands.

The vulnerability exists due to improper neutralization of special elements used in an OS command in the Glances action template rendering and execution pipeline when concatenating two adjacent unescaped Mustache variables in an administrator-configured action template. A local user can control neighboring stat fields so that shell operators are reconstructed across field boundaries to execute arbitrary commands.

Exploitation requires an administrator-configured action template that uses adjacent unescaped Mustache variables without a separator.


Affected software

glances

How to mitigate CVE-2026-68518

Install security update from vendor's website.

glances - update to 4.5.6

External References

Related Security Bulletins