PT-2026-33778 · Glance+1 · Glance+1

CVE-2026-35588

·

Published

2026-04-20

·

Updated

2026-07-08

CVSS v2.0

6.4

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions Glances versions prior to 4.5.4
Description The Cassandra export module (glances/exports/glances cassandra/ init .py) interpolates configuration values directly into CQL statements without validation. A user with write access to glances.conf can manipulate the keyspace, table, and replication factor variables to redirect all exported monitoring data, including CPU, memory, network, and disk I/O, to an attacker-controlled Cassandra keyspace. This leads to data exfiltration and data loss.
Recommendations Update to version 4.5.4.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10402
CVE-2026-35588
GHSA-GRP3-H8M8-45P7
OPENSUSE-SU-2026:10602-1
PYSEC-2026-2177

Affected Products

Glance
Red Os