CVE-2026-32596: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-32596 is an unauthenticated REST API exposure vulnerability in Glances, an open-source cross-platform system monitoring tool. When started in web server mode (glances -w), the server binds to all network interfaces (0.0.0.0:61208) and exposes its full REST API without any authentication by default, allowing any network client to retrieve sensitive system information. All versions prior to 4.5.2 are affected. The vulnerability was published on March 14, 2026, and patched in version 4.5.2 released the same day. It carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is a missing-by-default authentication control (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor). In glances/outputs/glances_restful_api.py, the APIRouter is initialized without any authentication dependency unless the --password flag is explicitly provided at startup; otherwise, self._password and self._jwt_handler are set to None. The server also defaults to binding on 0.0.0.0:61208, making it reachable from any network interface. Additionally, the process list plugin (glances/plugins/processlist/__init__.py) exposes the full cmdline field for every running process without sanitization, which can contain passwords, API keys, and tokens passed as command-line arguments. No preconditions beyond network reachability are required — exploitation requires only a standard HTTP client (GitHub Advisory).

Impact

An unauthenticated remote attacker can perform complete system reconnaissance by querying exposed endpoints including /api/4/system, /api/4/all, /api/4/processlist, /api/4/connections, /api/4/fs, and Docker container information. The most critical impact is credential harvesting: process command-line arguments exposed via /api/4/processlist may contain plaintext passwords, API keys, database credentials, and authentication tokens belonging to any running process. Harvested credentials can enable lateral movement to other systems and services, significantly expanding the blast radius beyond the monitored host itself (GitHub Advisory).

Exploitability

A proof-of-concept exploit consisting of concrete curl commands is publicly documented in the official security advisory, requiring no specialized tooling or prior access (GitHub Advisory). Nuclei templates for automated detection were added to the ProjectDiscovery nuclei-templates repository shortly after disclosure. The EPSS score is approximately 4.07% (89th percentile), indicating elevated exploitation probability relative to most CVEs. There is no confirmed evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. No specific threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Use Shodan, Censys, or similar tools to identify internet-facing hosts with port 61208 open, or scan internal networks for Glances instances running in web server mode.
  2. Verify target: Confirm the Glances API is accessible without authentication by sending a simple request: curl -s http://TARGET:61208/api/4/system | jq . — a successful JSON response confirms the target is vulnerable.
  3. Dump all system data: Retrieve a full system snapshot: curl -s http://TARGET:61208/api/4/all > system_dump.json — this captures CPU, memory, network, filesystem, and process data.
  4. Harvest credentials from process list: Query the process list and filter for credential-containing command lines:
curl -s http://TARGET:61208/api/4/processlist | \
  jq -r '.[] | select(.cmdline | tostring | test("password|api-key|token|secret"; "i")) | {pid, username, process: .name, cmdline}'
  1. Enumerate network connections and containers: Query /api/4/connections and /api/4/docker to map internal network topology and identify additional attack targets.
  2. Lateral movement: Use harvested credentials (passwords, API keys, tokens) to authenticate to other services identified through network connection data or process arguments (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP GET requests to http://<host>:61208/api/4/processlist, /api/4/all, /api/4/system, /api/4/connections, or /api/4/docker from external or untrusted IP addresses; high-volume or automated sequential API queries to port 61208.
  • Logs: Web server access logs for Glances showing repeated unauthenticated API requests from non-local IP addresses; requests to /api/4/all or /api/4/processlist with no Authorization header.
  • Process/Service: Glances process running with -w or --webserver flag and without --password flag, bound to 0.0.0.0 rather than 127.0.0.1; startup logs containing WARNING: Glances web server is running WITHOUT authentication (added in v4.5.2 as an informational indicator).

Mitigation and workarounds

Upgrade Glances to version 4.5.2 or later, which adds a startup warning when authentication is not configured (Glances v4.5.2 Release). If immediate patching is not possible, apply the following workarounds: (1) enable authentication by starting Glances with glances -w --password; (2) restrict the bind address to localhost with glances -w --bind 127.0.0.1 if remote access is not required; (3) use firewall rules to block external access to port 61208; or (4) place Glances behind a reverse proxy (nginx, Caddy, Apache) with TLS and authentication for any public-facing deployment (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher DhiyaneshGeek and credited in the official advisory (GitHub Advisory). Red Hat tracked the issue via Bugzilla and assigned it high severity (Red Hat Bugzilla). The disclosure generated coverage on social media platforms including Mastodon and Bluesky, and was picked up by security aggregators such as RedPacket Security. ProjectDiscovery added Nuclei detection templates for automated scanning shortly after disclosure, reflecting community interest in identifying exposed instances at scale.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

glances

Affected

sid

glances: 4.5.2+dfsg-1

Fixed

trixie

glances

Affected

Ubuntu

Unknown

bionic (esm-apps)

glances

Unknown

devel

glances

Unknown

focal (esm-apps)

glances

Unknown

jammy

glances

Unknown

jammy (esm-apps)

glances

Unknown

noble

glances

Unknown

noble (esm-apps)

glances

Unknown

resolute

glances

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management