PT-2026-25849 · Glance+1 · Glance+1

·

CVE-2026-32611

·

Publicado

2026-01-01

·

Atualizado

2026-05-08

CVSS v2.0

9.4

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Glances versions prior to 4.5.3
Description Glances, a system cross-platform monitoring tool, contains a SQL injection issue in the DuckDB export module. The TimescaleDB export module was previously fixed for SQL injection by using parameterized queries, but this fix was not applied to the DuckDB export module. Table and column names derived from monitoring statistics are directly interpolated into SQL statements via f-strings, specifically in the DDL construction and table name references. While INSERT values use parameterized queries, the table name and column names are not escaped or parameterized. This issue could lead to data integrity compromise or unauthorized table creation. The vulnerability exists because stat dictionary keys, potentially sourced from external data in future plugins, are used without proper sanitization in SQL queries.
Recommendations Update to Glances version 4.5.3 or later.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-07160
CVE-2026-32611
GHSA-49G7-2WW7-3VF5
OPENSUSE-SU-2026:10415-1
PYSEC-2026-2170

Produtos afetados

Glance
Red Os