Overly permissive cross-domain whitelist in glances - CVE-2026-68517
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to permissive cross-domain security policy enforcement in the REST API CORS credentials guard when processing a multi-origin allowlist that includes the wildcard. A remote attacker can host a malicious website to disclose sensitive information.
User interaction is required, and the victim must have previously authenticated to the Glances instance through their browser.