Junglewise Threat Intelligence

CVE-2026-46607: nicolargo Glances insecure pickle deserialization in version cache

CVE-2026-46607 · Severity: high · CVSS 7.8 · Published 2026-06-25

Technologies: glances (PyPI). Vendors: PyPI.

Executive brief

Glances is a system monitoring tool used to track hardware and software performance. A security flaw allows a local user or a compromised container to gain full control over the system by placing a malicious file in a predictable location used for version checking. If Glances is running with administrative privileges (root), an attacker could use this to take over the entire server or monitoring environment.

Technical details

The vulnerability exists in `glances/outdated.py` due to the use of `pickle.load()` on a version-check cache file (`glances-version.db`) stored in a predictable, world-accessible path (typically `~/.cache/glances/`). Because the `pickle` module is inherently unsafe and the application performs no integrity checks or signature verification before deserialization, an attacker with write access to the cache directory can plant a malicious pickle file. When Glances starts with version checking enabled (the default setting), it deserializes the file, leading to arbitrary code execution as the user running the process. This is particularly critical in deployments where Glances runs as root to access hardware counters. The issue is resolved in version 4.5.5 by replacing pickle with a safer format.

Affected products

  • nicolargo Glances < 4.5.5

Timeline

  • 2026-06-13: patched: Version 4.5.5 released
  • 2026-06-25: disclosed: NVD publication date

References

Related threats