CVE-2026-68519

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, GlancesActions.run() in glances/actions.py ignores --disable-config-exec for on-alert action commands and invokes secure_popen() with shell operators enabled, allowing configured redirection, command chaining, or pipes to execute when an alert triggers. This issue is fixed in 4.5.6.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-17 18:18

Updated : 2026-08-17 18:18


NVD link : CVE-2026-68519

Mitre link : CVE-2026-68519

CVE.ORG link : CVE-2026-68519


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')