CVE-2026-32611 is a critical SQL injection vulnerability (CWE-89) affecting nicolargo Glances, an open-source system monitoring tool, specifically within its DuckDB export module. This flaw allows unauthenticated attackers to inject malicious SQL via unescaped table and column names derived from monitoring statistics, which are directly interpolated into SQL statements. Rated with a CVSS score of 9.1 (CRITICAL), the vulnerability can be exploited remotely with low complexity and no user interaction or privileges required, leading to high impact on confidentiality and integrity. While severe, there is currently no evidence of active exploitation, nor are public exploit codes available. Community discussion and media coverage are minimal, and its EPSS score indicates a very low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.2CPE matchmatch criteria | cpe:2.3:a:nicolargo:glances:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.