
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33533 is a CORS misconfiguration vulnerability in the Glances XML-RPC server that enables cross-origin system information disclosure. The GlancesXMLRPCHandler class in glances/server.py unconditionally sets Access-Control-Allow-Origin: * on every HTTP response, and the server does not validate the Content-Type header, allowing browser-based cross-origin attacks without a preflight check. All versions of Glances before 4.5.3 are affected when running in server mode (glances -s). The vulnerability was disclosed on March 29–30, 2026, and has a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 7.1 (High) (GitHub Advisory).
The root cause is classified as CWE-942 (Permissive Cross-domain Policy with Untrusted Domains). In glances/server.py, the send_my_headers() method hardcodes Access-Control-Allow-Origin: *, and the underlying SimpleXMLRPCRequestHandler parses POST body content as XML regardless of the Content-Type header value. Because browsers classify POST requests with Content-Type: text/plain as CORS "simple requests," no OPTIONS preflight is triggered, allowing any attacker-controlled webpage to call XML-RPC methods such as getAll(), getPlugin(), getAllPlugins(), getAllLimits(), or getAllViews() and read the full response. The default configuration also has authentication disabled (server.isAuth = False), compounding the exposure. A related issue in the REST API was previously patched as CVE-2026-32610 in version 4.5.1, but the XML-RPC server — a completely separate code path — was not addressed until 4.5.3 (GitHub Advisory, Patch Commit).
Successful exploitation results in complete exfiltration of sensitive system monitoring data from the host running Glances in server mode. An attacker whose malicious webpage is visited by a user on the same network as the Glances server can silently retrieve hostname, OS version and distribution, IP addresses and subnet masks, CPU/memory/disk/network statistics, disk mount points, network interface details, sensor readings, and the full process list including command-line arguments — which frequently contain database credentials, API tokens, internal service URLs, and file paths. There is no integrity or availability impact, but the confidentiality breach can facilitate lateral movement by exposing credentials and internal network topology (GitHub Advisory).
Public proof-of-concept exploit code is available in the official security advisory, including a standalone Python script (poc_test.py) and a browser-based HTML/JavaScript page (poc_cors_xmlrpc.html) that demonstrate the full attack (GitHub Advisory). The vulnerability requires user interaction (a victim must visit the attacker's webpage while having network access to the Glances server), but no authentication or special privileges are needed. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.039% (18th percentile), indicating low but non-negligible exploitation probability (GitHub Advisory). Nessus detection plugin 304873 is available for scanning (Tenable).
Reconnaissance: Identify hosts running Glances in XML-RPC server mode (glances -s) on the default port 61209 using network scanners (e.g., Nmap: nmap -p 61209 <target_range>). Confirm the service by sending a test HTTP request and checking for the Access-Control-Allow-Origin: * response header.
Craft malicious webpage: Create an HTML page (or use the published poc_cors_xmlrpc.html PoC) that uses the browser's fetch() API to send a cross-origin POST request to the target Glances XML-RPC endpoint with Content-Type: text/plain to avoid triggering a CORS preflight check.
Send XML-RPC payload: The fetch request targets http://TARGET_IP:61209/RPC2 with a valid XML-RPC method call body (e.g., <?xml version="1.0"?><methodCall><methodName>getAll</methodName></methodCall>). Because Content-Type: text/plain is a CORS simple request, the browser sends it directly without an OPTIONS preflight.
Read cross-origin response: The Glances server processes the XML body, returns the full system monitoring dataset with Access-Control-Allow-Origin: *, and the attacker's JavaScript reads the response — bypassing the same-origin policy.
Exfiltrate data: Parse the XML-RPC response to extract hostname, OS details, IP addresses, process list with command lines (potentially containing credentials or tokens), disk and network information, and transmit it to an attacker-controlled server.
/RPC2 endpoint with Content-Type: text/plain and an Origin header from an external or untrusted domain; outbound HTTP responses containing large XML payloads with system monitoring data./RPC2 with Content-Type: text/plain from unexpected source IPs or origins; Glances server logs (if verbose logging enabled) showing getAll, getPlugin, or getAllPlugins method calls from non-local origins.-s or --server flag on a network-accessible interface without the -P/--password flag; cors_origins not explicitly restricted in glances.conf [outputs] section.The primary remediation is to upgrade Glances to version 4.5.3 or later, which makes the CORS origin configurable and defaults to a warning when running unauthenticated with wildcard CORS (Glances v4.5.3 Release, Patch Commit). If upgrading immediately is not possible, apply the following mitigations:
cors_origins=<trusted-origin> in the [outputs] section of glances.conf (now applies to both REST and XML-RPC servers in 4.5.3+).-P/--password to require credentials for XML-RPC access.-s/--server.The vulnerability was reported by researcher tanishqshah2 and published by the Glances maintainer (nicolargo) on March 29, 2026. The fix was included in the v4.5.3 release alongside a patch for a separate command injection vulnerability (CVE-2026-33641), and the release notes explicitly credit Tanishq Shah as a contributor (Glances v4.5.3 Release). No significant broader media coverage or notable community controversy has been identified beyond the standard advisory and vulnerability database entries.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."