Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authentication by default when started with `glances -w`, exposing REST API with sensitive system information including process command-lines containing credentials (passwords, API keys, tokens) to any network client. Version 4.5.2 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Mar 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authentication by default when started with `glances -w`, exposing REST API with sensitive system information including process command-lines containing credentials (passwords, API keys, tokens) to any network client. Version 4.5.2 fixes the issue. | |
| Title | Glances exposes the REST API without authentication | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-18T05:18:11.547Z
Reserved: 2026-03-12T14:54:24.269Z
Link: CVE-2026-32596
No data.
Status : Received
Published: 2026-03-18T06:16:18.800
Modified: 2026-03-18T06:16:18.800
Link: CVE-2026-32596
No data.
OpenCVE Enrichment
No data.