Overly permissive cross-domain whitelist in glances - CVE-2026-68517

 

Overly permissive cross-domain whitelist in glances - CVE-2026-68517

Published: August 3, 2026


Vulnerability identifier: #VU140773
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-68517
CWE-ID: CWE-942
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to permissive cross-domain security policy enforcement in the REST API CORS credentials guard when processing a multi-origin allowlist that includes the wildcard. A remote attacker can host a malicious website to disclose sensitive information.

User interaction is required, and the victim must have previously authenticated to the Glances instance through their browser.


Affected software

glances

How to mitigate CVE-2026-68517

Install security update from vendor's website.

glances - update to 4.5.6

External References

Related Security Bulletins