
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32596 is an unauthenticated REST API exposure vulnerability in Glances, an open-source cross-platform system monitoring tool. When started in web server mode (glances -w), the server binds to all network interfaces (0.0.0.0:61208) and exposes its full REST API without any authentication by default, allowing any network client to retrieve sensitive system information. All versions prior to 4.5.2 are affected. The vulnerability was published on March 14, 2026, and patched in version 4.5.2 released the same day. It carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause is a missing-by-default authentication control (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor). In glances/outputs/glances_restful_api.py, the APIRouter is initialized without any authentication dependency unless the --password flag is explicitly provided at startup; otherwise, self._password and self._jwt_handler are set to None. The server also defaults to binding on 0.0.0.0:61208, making it reachable from any network interface. Additionally, the process list plugin (glances/plugins/processlist/__init__.py) exposes the full cmdline field for every running process without sanitization, which can contain passwords, API keys, and tokens passed as command-line arguments. No preconditions beyond network reachability are required — exploitation requires only a standard HTTP client (GitHub Advisory).
An unauthenticated remote attacker can perform complete system reconnaissance by querying exposed endpoints including /api/4/system, /api/4/all, /api/4/processlist, /api/4/connections, /api/4/fs, and Docker container information. The most critical impact is credential harvesting: process command-line arguments exposed via /api/4/processlist may contain plaintext passwords, API keys, database credentials, and authentication tokens belonging to any running process. Harvested credentials can enable lateral movement to other systems and services, significantly expanding the blast radius beyond the monitored host itself (GitHub Advisory).
A proof-of-concept exploit consisting of concrete curl commands is publicly documented in the official security advisory, requiring no specialized tooling or prior access (GitHub Advisory). Nuclei templates for automated detection were added to the ProjectDiscovery nuclei-templates repository shortly after disclosure. The EPSS score is approximately 4.07% (89th percentile), indicating elevated exploitation probability relative to most CVEs. There is no confirmed evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. No specific threat actor attribution has been reported.
curl -s http://TARGET:61208/api/4/system | jq . — a successful JSON response confirms the target is vulnerable.curl -s http://TARGET:61208/api/4/all > system_dump.json — this captures CPU, memory, network, filesystem, and process data.curl -s http://TARGET:61208/api/4/processlist | \
jq -r '.[] | select(.cmdline | tostring | test("password|api-key|token|secret"; "i")) | {pid, username, process: .name, cmdline}'/api/4/connections and /api/4/docker to map internal network topology and identify additional attack targets.http://<host>:61208/api/4/processlist, /api/4/all, /api/4/system, /api/4/connections, or /api/4/docker from external or untrusted IP addresses; high-volume or automated sequential API queries to port 61208./api/4/all or /api/4/processlist with no Authorization header.-w or --webserver flag and without --password flag, bound to 0.0.0.0 rather than 127.0.0.1; startup logs containing WARNING: Glances web server is running WITHOUT authentication (added in v4.5.2 as an informational indicator).Upgrade Glances to version 4.5.2 or later, which adds a startup warning when authentication is not configured (Glances v4.5.2 Release). If immediate patching is not possible, apply the following workarounds: (1) enable authentication by starting Glances with glances -w --password; (2) restrict the bind address to localhost with glances -w --bind 127.0.0.1 if remote access is not required; (3) use firewall rules to block external access to port 61208; or (4) place Glances behind a reverse proxy (nginx, Caddy, Apache) with TLS and authentication for any public-facing deployment (GitHub Advisory).
The vulnerability was reported by security researcher DhiyaneshGeek and credited in the official advisory (GitHub Advisory). Red Hat tracked the issue via Bugzilla and assigned it high severity (Red Hat Bugzilla). The disclosure generated coverage on social media platforms including Mastodon and Bluesky, and was picked up by security aggregators such as RedPacket Security. ProjectDiscovery added Nuclei detection templates for automated scanning shortly after disclosure, reflecting community interest in identifying exposed instances at scale.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."