PT-2026-25820 · Glance+1 · Glance+1

Restriction

·

Published

2026-01-01

·

Updated

2026-05-08

·

CVE-2026-32633

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Glances versions prior to 4.5.2
Description Glances, an open-source system cross-platform monitoring tool, contains a critical issue in its Central Browser mode. The /api/4/serverslist endpoint returns raw server objects that can contain embedded HTTP Basic credentials for downstream Glances servers. If the Glances Browser/API instance is started without the --password flag, which is common in internal network deployments, this endpoint is completely unauthenticated. This allows any network user who can reach the Browser API to retrieve reusable credentials for protected downstream Glances servers. The issue arises because server objects are mutated in-place during background polling, and the uri field may contain credentials derived from a reusable Glances authentication secret. The uri field is not sanitized before being returned in the API response. The vulnerability allows for credential replay against downstream Glances servers.
Recommendations Upgrade to Glances version 4.5.2 or later to resolve this issue.

Exploit

Fix

Insufficiently Protected Credentials

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07159
CVE-2026-32633
GHSA-R297-P3V4-WP8M
OPENSUSE-SU-2026:10415-1

Affected Products

Glance
Red Os