Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-33641

5 месяцев назад

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic configuration values in which substrings enclosed in backticks are executed as system commands during configuration parsing. This behavior occurs in Config.get_value() and is implemented without validation or restriction of the executed commands. If an attacker can modify or influence configuration files, arbitrary commands will execute automatically with the privileges of the Glances process during startup or configuration reload. In deployments where Glances runs with elevated privileges (e.g., as a system service), this may lead to privilege escalation. This issue has been patched in version 4.5.3.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-33641

5 месяцев назад

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic configuration values in which substrings enclosed in backticks are executed as system commands during configuration parsing. This behavior occurs in Config.get_value() and is implemented without validation or restriction of the executed commands. If an attacker can modify or influence configuration files, arbitrary commands will execute automatically with the privileges of the Glances process during startup or configuration reload. In deployments where Glances runs with elevated privileges (e.g., as a system service), this may lead to privilege escalation. This issue has been patched in version 4.5.3.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-33641

5 месяцев назад

Glances is an open-source system cross-platform monitoring tool. Prior ...

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20260709-80-0043

около 1 месяца назад

Уязвимость glances

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-qhj7-v7h7-q4c7

5 месяцев назад

Glances Vulnerable to Command Injection via Dynamic Configuration Values

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2026-11020

5 месяцев назад

Уязвимость функции Config.get_value() инструмента мониторинга Glances, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-33641

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic configuration values in which substrings enclosed in backticks are executed as system commands during configuration parsing. This behavior occurs in Config.get_value() and is implemented without validation or restriction of the executed commands. If an attacker can modify or influence configuration files, arbitrary commands will execute automatically with the privileges of the Glances process during startup or configuration reload. In deployments where Glances runs with elevated privileges (e.g., as a system service), this may lead to privilege escalation. This issue has been patched in version 4.5.3.

CVSS3: 7.8
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-33641

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic configuration values in which substrings enclosed in backticks are executed as system commands during configuration parsing. This behavior occurs in Config.get_value() and is implemented without validation or restriction of the executed commands. If an attacker can modify or influence configuration files, arbitrary commands will execute automatically with the privileges of the Glances process during startup or configuration reload. In deployments where Glances runs with elevated privileges (e.g., as a system service), this may lead to privilege escalation. This issue has been patched in version 4.5.3.

CVSS3: 7.8
1%
Низкий
5 месяцев назад
debian логотип
CVE-2026-33641

Glances is an open-source system cross-platform monitoring tool. Prior ...

CVSS3: 7.8
1%
Низкий
5 месяцев назад
redos логотип
ROS-20260709-80-0043

Уязвимость glances

CVSS3: 7.8
1%
Низкий
около 1 месяца назад
github логотип
GHSA-qhj7-v7h7-q4c7

Glances Vulnerable to Command Injection via Dynamic Configuration Values

CVSS3: 7.8
1%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-11020

Уязвимость функции Config.get_value() инструмента мониторинга Glances, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.8
1%
Низкий
5 месяцев назад

Уязвимостей на страницу