CVE-2026-46608
Reported by GitHub_M · Published June 25, 2026
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s) introduced a configurable CORS origin list in version 4.5.3 as a mitigation for CVE-2026-33533. However, the implementation silently falls back to Access-Control-Allow-Origin: * whenever cors_origins contains more than one entry. An operator who configures an explicit two-entry allowlist (e.g. two internal dashboard origins) intending to restrict browser access instead receives the unrestricted wildcard. A malicious web page served from any origin can issue a CORS simple request to /RPC2 and read the full system monitoring dataset without the victim's knowledge. This vulnerability is fixed in 4.5.5.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| nicolargo | glances | < 4.5.5 |
| nicolargo | glances | < 4.5.5, < 4.5.5, < 4.5.5 |
| PyPI | Glances | 0 |
Timeline
- Jun 22, 2026 CVE Published
- Jun 26, 2026 Coalition ESS Score
- Jun 26, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
- Sep 6, 2026 EPSS Score
References
- https://github.com/nicolargo/glances/security/advisories/GHSA-87qc-fj39-wccr x_refsource_CONFIRM
- https://github.com/nicolargo/glances/releases/tag/v4.5.5 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-46608 advisory
- https://github.com/advisories/GHSA-87qc-fj39-wccr advisory
- https://github.com/nicolargo/glances url
- https://github.com/pypa/advisory-database/tree/main/vulns/glances/PYSEC-2026-2495.yaml advisory
- https://pypi.org/project/glances url