Impact
Glances web mode can expose REST API telemetry to any client that can reach the service when authentication is not enabled [S2][S5]. Advisory data for CVE-2026-32596 highlights the risk of sensitive system information and process command-line exposure on affected deployments [S1][S2]. Current Glances documentation also treats unauthenticated mode as a trusted-network default, so public or semi-public reachability is the exposure that matters [S4][S5].
Root Cause
The Glances REST API can run without a password or API token, and the web server may bind on network interfaces that are reachable beyond localhost [S2][S5]. Version 4.5.2 added warning and hardening behavior for this condition, but release notes state that unauthenticated mode can remain available for private-network deployments [S4].
Covered by FixVibe
FixVibe's verified active scans flag Glances REST APIs on the scanned origin that return monitoring data without credentials [S5], and show the response status and API version.
Fix
Require Glances authentication with --password or token-based access, bind the service to localhost when remote access is not needed, place it behind a TLS/authenticated reverse proxy or VPN, configure webui_allowed_hosts, and restrict firewall exposure to trusted networks [S5]. Upgrade to 4.5.2 or newer for the latest warning and hardening behavior, then verify unauthenticated requests to the reported API path return 401/403 or are unreachable [S2][S4].
