CVE-2026-32610 affects Glances versions prior to 4.5.2, stemming from a misconfigured Cross-Origin Resource Sharing (CORS) policy in its REST API web server. This critical vulnerability (CVSS 8.1 HIGH) allows remote attackers, with user interaction, to make credentialed cross-origin API requests, leading to high confidentiality and integrity impacts through the theft of sensitive system monitoring data, configuration secrets, and command-line arguments. While exploitation has low complexity, there is no evidence of active exploitation, nor are public exploit modules currently available, and community attention remains very low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.2CPE matchmatch criteria | cpe:2.3:a:nicolargo:glances:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.