CVE-2026-30930 is a critical SQL injection vulnerability (CVSS 9.8) affecting Glances versions prior to 4.5.1. This flaw allows unauthenticated attackers to execute arbitrary SQL commands via unsanitized system monitoring data, such as process names or container names, leading to full compromise of the database. The vulnerability is network-exploitable with low complexity, requiring no user interaction or privileges. While there is currently no evidence of active exploitation or public exploit code, organizations using affected Glances versions should upgrade to 4.5.1 immediately to mitigate this significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.1CPE matchmatch criteria | cpe:2.3:a:nicolargo:glances:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.