
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33641 is a command injection vulnerability in the Glances system monitoring tool, classified as "Command Injection via Dynamic Configuration Values." It affects all Glances versions up to and including 4.5.2 (pip package), and was disclosed on March 29–30, 2026, with a patch released in version 4.5.3. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Glances Security Advisory).
The root cause is CWE-78 (Improper Neutralization of Special Elements used in an OS Command). Glances' Config.get_value() function in glances/config.py uses a regex pattern to find substrings enclosed in backticks within configuration values and passes them directly to system_exec() in glances/globals.py, which executes them via subprocess.run() without any validation or sanitization. This execution occurs automatically every time a configuration value is read — during startup or configuration reload — requiring no user interaction beyond the initial configuration file modification. An attacker must have local access sufficient to write to or influence a Glances configuration file (e.g., user-level write access to config directories) (GitHub Advisory, Glances Security Advisory).
Successful exploitation allows a local attacker to execute arbitrary OS commands with the full privileges of the Glances process, resulting in high confidentiality, integrity, and availability impact. If Glances is deployed as a system service running as root or another privileged account, this vulnerability enables privilege escalation. Vulnerable scenarios include misconfigured file permissions, shared systems with writable configuration directories, container environments with mounted configuration volumes, and automated configuration management pipelines that ingest untrusted data (GitHub Advisory).
A proof-of-concept (PoC) exploit with step-by-step reproduction instructions is publicly available in the GitHub security advisory, and an exploit entry has also appeared on Exploit-DB (exploit ID 52559) (Glances Security Advisory). The PoC demonstrates arbitrary command execution using a crafted configuration file with a backtick-enclosed command (e.g., `id`). As of the time of reporting, there is no evidence of active in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.018% (per Feedly data), though the GitHub Advisory Database lists it at 0.737% (73rd percentile). The vulnerability is not currently listed in the CISA KEV catalog (GitHub Advisory).
systemctl status glances or checking installed pip packages with pip show glances).~/.config/glances/glances.conf), a system-level path, or a custom path passed via the -C flag. This may exploit misconfigured directory permissions, a shared system account, or a writable container volume mount./tmp/glances.conf with the following content:[outputs]
url_prefix = `id`glances -C /tmp/glances.conf. Alternatively, if Glances is already running as a service, modify its active configuration file and wait for a reload or restart.id in the PoC) is automatically executed via subprocess.run() with the privileges of the Glances process, and its output replaces the configuration value — with no further user interaction required (Glances Security Advisory).glances.conf) containing backtick-enclosed strings in any configuration value field; new files created in /tmp or other writable directories by the Glances process owner./bin/sh, /bin/bash, curl, wget, python, nc) visible via ps or process auditing tools like auditd./var/log/audit/audit.log) showing execve syscalls initiated by the Glances process for unexpected commands; application logs showing configuration reload events followed by anomalous subprocess activity.Upgrade Glances to version 4.5.3 or later, which includes the security patch for CVE-2026-33641 (commit 358d76a) (Glances Release v4.5.3, Patch Commit). As interim mitigations: restrict write access to all Glances configuration file paths to authorized users only; run Glances with the minimum necessary privileges (avoid running as root or a highly privileged service account); and audit configuration files for any backtick-enclosed substrings. Monitor configuration file modifications using file integrity monitoring tools.
The vulnerability was reported by security researcher mith36 and published by the Glances maintainer (nicolargo) on March 29, 2026. The fix was included in the v4.5.3 release alongside a patch for a separate CORS-related vulnerability (CVE-2026-33533), indicating a coordinated security release (Glances Release v4.5.3). Tenable added detection via Nessus plugin 304886, and the vulnerability was indexed by multiple threat intelligence platforms including VulDB and CIRCL (Glances Security Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."