Executive brief
Glances is a system monitoring tool used to track performance metrics like CPU, memory, and running processes. A security flaw in its server mode allows malicious websites to bypass access restrictions and steal sensitive system data if the administrator tries to set up multiple authorized dashboards. This could result in the exposure of hostnames, process lists, and potentially sensitive credentials contained in command-line arguments to unauthorized third parties.
Technical details
The Glances XML-RPC server (glances -s) fails to correctly handle multiple entries in the 'cors_origins' configuration. In `glances/server.py`, the implementation logic `self.cors_origin = cors_origins[0] if len(cors_origins) == 1 else "*"` causes any allowlist with two or more entries to collapse into a global wildcard. Because the server responds with 'Access-Control-Allow-Origin: *' for POST requests with 'text/plain' content types (CORS simple requests), a malicious webpage can use the fetch API to read the full system monitoring dataset (via the /RPC2 endpoint) from a victim's browser. This vulnerability is an incomplete fix for CVE-2026-33533 and is resolved in version 4.5.5.
Affected products
- nicolargo Glances >= 4.5.3, < 4.5.5
Timeline
- 2026-06-13: patched: Version 4.5.5 released
- 2026-06-25: disclosed: NVD publication date