CVE-2026-32634 impacts Glances, an open-source system monitoring tool, in versions prior to 4.5.2, where it improperly uses untrusted Zeroconf-advertised server names for connection URIs and password lookups in Central Browser mode. This vulnerability, rated 8.1 HIGH, allows an attacker on the same local network to advertise a fake Glances service, causing the browser to automatically send reusable authentication secrets to an attacker-controlled host, leading to high confidentiality and integrity impact. There is currently no evidence of active exploitation, no public exploit code available, and community attention for this vulnerability is very low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.2CPE matchmatch criteria | cpe:2.3:a:nicolargo:glances:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.