CVE-2026-30928

Severity CVSS v4.0:
HIGH
Type:
CWE-200 Information Leak / Disclosure
Publication date:
10/03/2026
Last modified:
17/03/2026

Description

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint returns the entire parsed Glances configuration file (glances.conf) via self.config.as_dict() with no filtering of sensitive values. The configuration file contains credentials for all configured backend services including database passwords, API tokens, JWT signing keys, and SSL key passwords. This vulnerability is fixed in 4.5.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nicolargo:glances:*:*:*:*:*:*:*:* 4.5.1 (excluding)