SCA: security update for Glances (GHSA-r297-p3v4-wp8m)

critical Tenable Cloud Security Plugin ID 438844

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central
Browser mode, the `/api/4/serverslist` endpoint returns raw server objects from
`GlancesServersList.get_servers_list()`. Those objects are mutated in-place during background polling and
can contain a `uri` field with embedded HTTP Basic credentials for downstream Glances servers, using the
reusable pbkdf2-derived Glances authentication secret. If the front Glances Browser/API instance is
started without `--password`, which is supported and common for internal network deployments,
`/api/4/serverslist` is completely unauthenticated. Any network user who can reach the Browser API can
retrieve reusable credentials for protected downstream Glances servers once they have been polled by the
browser instance. Version 4.5.2 fixes the issue. (CVE-2026-32633)

Solution

Update the Glances library and its related packages to version 4.5.2 or later.

See Also

https://github.com/advisories/GHSA-r297-p3v4-wp8m

Plugin Details

Severity: Critical

ID: 438844

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 3/16/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.59

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-32633

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/16/2026

Vulnerability Publication Date: 3/16/2026

Reference Information

CVE: CVE-2026-32633