
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32611 is a SQL injection vulnerability in the DuckDB export module of Glances, an open-source cross-platform system monitoring tool. The flaw arises because table names and column names derived from monitoring statistics are directly interpolated into SQL DDL statements via Python f-strings without sanitization. It affects all Glances versions prior to 4.5.2. The vulnerability was published on March 14, 2026, and assigned a CVSS v3.1 score of 7.0 (High) by the GitHub Advisory Database (GitHub Advisory), though Feedly's estimate places it at 9.1 (Critical) based on a different vector assessment (Feedly).
The root cause (CWE-89) is improper neutralization of SQL special elements in the DuckDB export module (glances/exports/glances_duckdb/__init__.py). Specifically, the export() method constructs CREATE TABLE and INSERT INTO statements by directly embedding the plugin name and stat dictionary keys (from creation_list) into f-strings without quoting or escaping SQL identifiers. While INSERT values correctly use ? parameterized placeholders, the DDL identifier names do not. This is an incomplete patch scenario: an identical vulnerability was previously fixed in the TimescaleDB export module (GHSA-x46r, commit 39161f0) using psycopg.sql.Identifier(), but the fix was never applied to the sibling DuckDB module. The primary attack vector requires that a Glances plugin produce stat dictionary keys from external or user-controlled data (e.g., container labels, custom metric names, SNMP OID labels); if such a plugin exists or is added, a crafted key like "cpu BIGINT); DROP TABLE secrets; --" would be injected verbatim into the CREATE TABLE statement (GitHub Advisory, Glances Security Advisory).
Successful exploitation can allow an unauthenticated network attacker to execute arbitrary SQL commands against the DuckDB database used by Glances, resulting in high confidentiality and integrity impact. An attacker could corrupt the DuckDB database, create unauthorized tables, drop existing tables, or modify the database schema in ways that affect other applications reading from the same database file. Availability impact is assessed as low to none, as the primary risks are data exposure and data integrity compromise rather than service disruption (GitHub Advisory, Feedly).
There is no confirmed in-the-wild exploitation of CVE-2026-32611, and no weaponized exploit code is publicly available. The GitHub Advisory notes that the provided PoC is a hypothetical injection scenario demonstrating the vulnerable code path rather than a functional attack against a live deployment (Glances Security Advisory). The EPSS score is approximately 0.018% (5th percentile), indicating a very low near-term exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation currently requires a precondition: a Glances plugin must generate stat dictionary keys from external or user-controlled data, which is not the default behavior with built-in plugins (GitHub Advisory).
[duckdb] section enabled in glances.conf."cpu BIGINT); DROP TABLE cpu; --". This key would be appended to creation_list as "cpu BIGINT); DROP TABLE cpu; -- VARCHAR".--export duckdb). The vulnerable export() method constructs the CREATE TABLE statement by directly interpolating the malicious key into the f-string, resulting in: CREATE TABLE plugin_name (time TIMETZ, hostname_id VARCHAR, cpu BIGINT); DROP TABLE cpu; -- VARCHAR);glances --export duckdb --debug 2>&1 | grep "Create table" (Glances Security Advisory).--debug) showing Create table: lines with SQL metacharacters (;, --, DROP, CREATE) embedded in table or column name positions in glances_duckdb/__init__.py output./tmp/glances.duckdb or the configured database path); missing tables that should exist (e.g., cpu, network) indicating a successful DROP TABLE injection.CREATE TABLE statements.Upgrade Glances to version 4.5.2 or later, which introduces a _quote_identifier() helper function that wraps all SQL identifiers (table names and column names) in double quotes with proper escaping of embedded double quotes, preventing injection (Glances Release v4.5.2, Patch Commit). The Red Hat Bugzilla entry notes that version 4.5.3 provides a more complete fix (Red Hat Bugzilla). As a workaround for those unable to upgrade immediately, disable the DuckDB export module by removing or commenting out the [duckdb] section in glances.conf. Additionally, audit any custom Glances plugins to ensure stat dictionary keys are not derived from external or user-controlled data sources.
Red Hat tracked the vulnerability via Bugzilla (Bug 2448682) and classified it as high severity, with the Product Security DevOps Team assigned for response (Red Hat Bugzilla). The Glances maintainer (nicolargo) published the advisory and patch on March 14, 2026, crediting the reporter "offset" for discovery, and the release notes for v4.5.2 acknowledged the fix alongside seven other security patches addressed in the same release (Glances Release v4.5.2). No significant broader media coverage or notable community debate has been identified beyond standard vulnerability tracking aggregators.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."