Junglewise Threat Intelligence

CVE-2026-46606: nicolargo Glances command injection in virsh.py

CVE-2026-46606 · Severity: high · CVSS 7.8 · Published 2026-06-25

Technologies: glances (PyPI). Vendors: PyPI.

Executive brief

Glances is a popular open-source tool used to monitor the performance of servers and virtual machines. A security flaw in its KVM/QEMU monitoring component allows a user with the ability to name or rename virtual machines to execute unauthorized commands on the host system. Because Glances often runs with high privileges (such as root) to collect system data, an attacker could potentially take full control of the server, access sensitive data, or disrupt operations.

Technical details

An OS command injection vulnerability (CWE-78) exists in the Glances KVM/QEMU monitoring engine within `glances/plugins/vms/engines/virsh.py`. The application reads VM domain names from `virsh list --all` and interpolates them into f-string command templates processed by `secure_popen()`. Because `secure_popen()` is designed to interpret shell operators like `&&`, `|`, and `>`, and domain names are not sanitized, an attacker can craft a VM name containing these operators to achieve arbitrary code execution. This requires the attacker to have local privileges to create or rename KVM/QEMU virtual machines (e.g., membership in the `libvirt` group). The vulnerability is fixed in version 4.5.5 by improving input handling.

Affected products

  • nicolargo Glances < 4.5.5

Timeline

  • 2026-06-13: patched: Version 4.5.5 released
  • 2026-06-25: disclosed: CVE-2026-46606 published

References

Related threats