
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30930 is a SQL injection vulnerability in the TimescaleDB export module of Glances, an open-source cross-platform system monitoring tool. The flaw exists in all versions prior to 4.5.1 (specifically confirmed in 4.5.0) and was published on March 10, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 7.3 (High) (GitHub Advisory, Red Hat).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The vulnerable normalize() method in glances/exports/glances_timescaledb/__init__.py wraps string values in single quotes using f"'{value}'" without escaping embedded single quotes, and the resulting strings are concatenated directly into INSERT queries executed via cur.execute() — no parameterized queries are used. An attacker can control input through process names, filesystem mount points, network interface names, or container names, injecting arbitrary SQL that is executed against the TimescaleDB (PostgreSQL) backend. The fix in version 4.5.1 replaces string concatenation with psycopg.sql parameterized queries and sql.Identifier/sql.Placeholder constructs throughout the export module (GitHub Advisory, Patch Commit).
Successful exploitation allows an attacker to execute arbitrary SQL commands against the TimescaleDB/PostgreSQL database backing Glances, enabling data destruction (DROP TABLE, DELETE, TRUNCATE), data exfiltration (via COPY ... TO or subqueries), and potential remote code execution via PostgreSQL extensions such as COPY ... PROGRAM. Any local user who can create a process with a crafted name can inject SQL, potentially compromising the entire PostgreSQL instance and enabling privilege escalation within the database environment (GitHub Advisory).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, providing exact payloads and step-by-step reproduction instructions against a real Glances deployment. The CVSS v4.0 exploit maturity is rated PROOF_OF_CONCEPT. The EPSS score is approximately 0.016% (0.000160), indicating low current exploitation probability. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Detection is available via Nessus plugin 301848 (GitHub Advisory, Tenable).
exec -a "x'); COPY (SELECT version()) TO '/tmp/sqli_proof.txt' --" python3 -c 'import time; [sum(range(500000)) or time.sleep(0.01) for _ in iter(int, 1)]'glances --export timescaledb --export-process-filter ".*" --time 5 --stdout cpunormalize() function, and concatenates it into an INSERT query. The injected SQL breaks out of the string literal and executes the attacker-controlled statement against the database./tmp/sqli_proof.txt). Escalate by using COPY ... PROGRAM for OS command execution, or exfiltrate/destroy database contents (GitHub Advisory).COPY, DROP, SELECT, INSERT) visible in process listings or Glances logs./tmp or other world-writable directories (e.g., /tmp/sqli_proof.txt) owned by the PostgreSQL service account, indicating successful COPY ... TO execution.--stdout or log file) showing INSERT queries containing unescaped SQL syntax; PostgreSQL logs recording unexpected COPY, DROP, or SELECT statements originating from the Glances database user.COPY ... PROGRAM entries in PostgreSQL's pg_stat_activity or audit logs (GitHub Advisory).Upgrade Glances to version 4.5.1 or later, which replaces all vulnerable string-concatenated SQL with parameterized queries using psycopg.sql (Glances Release, Patch Commit). If immediate patching is not possible, restrict network access to the Glances monitoring tool and its TimescaleDB backend to trusted internal networks only, and disable the TimescaleDB export module. Additionally, apply least-privilege principles to the database user account used by Glances to limit the impact of any successful injection (GitHub Advisory).
The vulnerability was reported by researchers theamanrawat and neo-ai-engineer and acknowledged by the Glances maintainer (nicolargo), who released the fix in version 4.5.1 on March 7, 2026. Red Hat tracked the issue via Bugzilla (Bug 2446050) and rated it high severity. The CVE received automated coverage from vulnerability tracking services including VulDB and Bluesky CVE feeds shortly after disclosure (Red Hat Bugzilla, GitHub Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."