PT-2026-33778 · Glance · Glance

Published

2026-04-20

·

Updated

2026-04-22

·

CVE-2026-35588

CVSS v3.1

6.3

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Glances versions prior to 4.5.4
Description The Cassandra export module (glances/exports/glances cassandra/ init .py) interpolates configuration values directly into CQL statements without validation. A user with write access to glances.conf can manipulate the keyspace, table, and replication factor variables to redirect all exported monitoring data, including CPU, memory, network, and disk I/O, to an attacker-controlled Cassandra keyspace. This leads to data exfiltration and data loss.
Recommendations Update to version 4.5.4.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-35588
GHSA-GRP3-H8M8-45P7
OPENSUSE-SU-2026:10602-1

Affected Products

Glance