FixVibe

high

Glances REST API Unauthenticated Access (CVE-2026-32596)

Glances can expose REST API telemetry without authentication when its web server is reachable from untrusted networks. FixVibe verified active scans flag Glances REST APIs that return monitoring data without credentials on the scanned origin.

CVE-2026-32596GHSA-wvxv-4j8q-4wjqCWE-200

Impact

Glances web mode can expose REST API telemetry to any client that can reach the service when authentication is not enabled [S2][S5]. Advisory data for CVE-2026-32596 highlights the risk of sensitive system information and process command-line exposure on affected deployments [S1][S2]. Current Glances documentation also treats unauthenticated mode as a trusted-network default, so public or semi-public reachability is the exposure that matters [S4][S5].

Root Cause

The Glances REST API can run without a password or API token, and the web server may bind on network interfaces that are reachable beyond localhost [S2][S5]. Version 4.5.2 added warning and hardening behavior for this condition, but release notes state that unauthenticated mode can remain available for private-network deployments [S4].

Covered by FixVibe

FixVibe's verified active scans flag Glances REST APIs on the scanned origin that return monitoring data without credentials [S5], and show the response status and API version.

Fix

Require Glances authentication with --password or token-based access, bind the service to localhost when remote access is not needed, place it behind a TLS/authenticated reverse proxy or VPN, configure webui_allowed_hosts, and restrict firewall exposure to trusted networks [S5]. Upgrade to 4.5.2 or newer for the latest warning and hardening behavior, then verify unauthenticated requests to the reported API path return 401/403 or are unreachable [S2][S4].