CVE-2026-30928: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-30928 is an unauthenticated configuration secrets exposure vulnerability in Glances, an open-source cross-platform system monitoring tool. The /api/4/config REST API endpoint returns the entire parsed glances.conf configuration file — including database passwords, API tokens, JWT signing keys, and SSL key passwords — with no filtering or redaction applied. All versions prior to 4.5.1 are affected. The vulnerability was published on March 7, 2026, and patched in version 4.5.1 released the same day. It carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (Github Advisory, Glances Advisory).

Technical details

The root cause (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) lies in two compounding flaws. First, the as_dict() method in glances/config.py iterates over every section and key in the ConfigParser object and returns them all as a flat dictionary with no sensitive key filtering. Second, when Glances is started without a password (glances -w), the API router is instantiated without any authentication dependency, meaning the /api/4/config, /api/4/config/{section}, and /api/4/config/{section}/{item} endpoints are fully unauthenticated and network-accessible on port 61208. An attacker only needs network reachability to the Glances web server — no credentials, no prior access, and no user interaction are required. The fix introduces a new as_dict_secure() method that blocks the passwords section entirely and redacts keys matching patterns such as password, token, secret, api_key, apikey, and ssl_keyfile (Glances Advisory, Patch Commit).

Impact

Successful exploitation allows any unauthenticated, network-reachable attacker to retrieve the full Glances configuration, exposing credentials for all configured backend services — including InfluxDB, MongoDB, PostgreSQL/TimescaleDB, CouchDB, and Cassandra — as well as JWT signing keys (enabling token forgery) and SSL private key passwords. The confidentiality impact is high, with no direct integrity or availability impact on the Glances host itself. However, the stolen credentials enable lateral movement and full compromise of connected backend infrastructure, significantly amplifying the real-world blast radius beyond the monitoring tool itself (Glances Advisory, Github Advisory).

Exploitability

A proof-of-concept exploit is publicly documented in the official security advisory, consisting of simple curl commands requiring no special tooling or authentication. The EPSS score is approximately 6.67% (91st percentile), indicating elevated exploitation probability relative to most CVEs. Multiple Nuclei templates have been added to the ProjectDiscovery repository to automate detection of this vulnerability. As of the time of reporting, there is no confirmed evidence of active in-the-wild exploitation, and the vulnerability is not listed in the CISA KEV catalog. No specific threat actor attribution has been made (Github Advisory, Glances Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Glances instances running in web server mode (default port 61208) using tools like Shodan, Censys, or Nuclei templates targeting the /api/4/config endpoint.
  2. Confirm vulnerability: Send a simple HTTP GET request to verify the endpoint is accessible and returns configuration data:
    curl http://target:61208/api/4/config
  3. Extract full configuration: The response contains the entire glances.conf as JSON, including all credentials in plaintext.
  4. Target specific secrets: Query sub-endpoints to extract individual credentials:
    # JWT signing key (enables token forgery)
    curl http://target:61208/api/4/config/outputs/jwt_secret_key
    # InfluxDB API token
    curl http://target:61208/api/4/config/influxdb2/token
    # All stored server passwords
    curl http://target:61208/api/4/config/passwords
  5. Leverage credentials: Use the extracted database passwords, API tokens, and JWT keys to authenticate directly to connected backend services (InfluxDB, MongoDB, PostgreSQL, etc.) or forge JWT tokens for further access (Glances Advisory, Github Advisory).

Indicators of compromise

  • Network: Unexpected HTTP GET requests to http://<host>:61208/api/4/config, /api/4/config/outputs/jwt_secret_key, /api/4/config/influxdb2/token, or /api/4/config/passwords from external or untrusted IP addresses.
  • Network: Unusual outbound connections from the Glances host to external IPs shortly after API access, potentially indicating credential use against backend services.
  • Logs: Glances web server access logs showing repeated or automated requests to /api/4/config endpoints, particularly from non-administrative source IPs or at unusual hours.
  • Logs: Subsequent authentication events in backend database or API service logs (InfluxDB, MongoDB, PostgreSQL) from unfamiliar source IPs using credentials stored in glances.conf.
  • File System: Presence of Glances configuration file (glances.conf) containing plaintext credentials in world-readable locations (e.g., ~/.config/glances/glances.conf or /etc/glances/glances.conf) (Glances Advisory).

Mitigation and workarounds

Upgrade Glances to version 4.5.1 or later, which introduces the as_dict_secure() method that redacts sensitive keys and blocks the passwords section from unauthenticated API responses (Glances Release, Patch Commit). If immediate patching is not possible, restrict network access to port 61208 via firewall rules or network segmentation to trusted hosts only, or start Glances with a password (glances -w --password) to enforce authentication on all API endpoints. As a precautionary measure, rotate all credentials (database passwords, API tokens, JWT signing keys, SSL key passwords) stored in glances.conf on any system that may have been exposed, regardless of whether exploitation is confirmed (Github Advisory).

Community reactions

The vulnerability was reported by researchers theamanrawat and neo-ai-engineer and was promptly addressed by the Glances maintainer with a same-day patch release. Red Hat tracked the issue via Bugzilla (Bug 2446053) and classified it as high severity. The vulnerability received attention on Bluesky and was picked up by automated CVE tracking accounts. Multiple Nuclei detection templates were contributed to the ProjectDiscovery repository within weeks of disclosure, reflecting active community interest in scanning for exposed instances (Red Hat Bugzilla, Glances Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

glances

Fixed

sid

glances: 4.5.1+dfsg-1

Fixed

trixie

glances

Affected

Ubuntu

Unknown

bionic (esm-apps)

glances

Unknown

devel

glances

Unknown

focal (esm-apps)

glances

Unknown

jammy

glances

Unknown

jammy (esm-apps)

glances

Unknown

noble

glances

Unknown

noble (esm-apps)

glances

Unknown

resolute

glances

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management