๐Ÿ” CVE Alert

CVE-2026-35588

MEDIUM 6.3

Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Cassandra export module (`glances/exports/glances_cassandra/__init__.py`) interpolates `keyspace`, `table`, and `replication_factor` configuration values directly into CQL statements without validation. A user with write access to `glances.conf` can redirect all monitoring data to an attacker-controlled Cassandra keyspace. Version 4.5.4 contains a fix.

CWE CWE-89
Vendor nicolargo
Product glances
Published Apr 20, 2026
Stay Ahead of the Next One

Get instant alerts for nicolargo glances

Be the first to know when new medium vulnerabilities affecting nicolargo glances are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

nicolargo / glances
< 4.5.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/nicolargo/glances/security/advisories/GHSA-grp3-h8m8-45p7 github.com: https://github.com/nicolargo/glances/commit/d339181f03a14bb15506307e9d58f876e23d8160 github.com: https://github.com/nicolargo/glances/commit/e41b665576f9fd5374e3152078726cc59a01e48c