What is CVE-2026-68517?
CVE-2026-68517 is a CORS misconfiguration vulnerability in the Glances monitoring tool before version 4.5.6. The `cors_origins` check incorrectly allows authentication data (`cors_credentials`) exposure when an origin list contains a wildcard due to flawed exact match logic. Affected users should immediately upgrade to version 4.5.6 or later.
Azərbaycanca: CVE-2026-68517, Glances monitorinq alətində CORS mənşə yoxlamasında zəiflikdir. 4.5.6 əvvəl versiyalarda `cors_origins` siyahısında wildcard (`*`) düzgün yoxlanılmadığı üçün, autentifikasiya məlumatları (`cors_credentials`) gözlənilməz mənbələrə sızır. Təsirə məruz qalan sistemlər dərhal 4.5.6 və ya yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of Glances are affected by CVE-2026-68517?
This vulnerability affects versions prior to 4.5.6.
What can this CORS misconfiguration lead to?
It can lead to the exposure of authentication data (`cors_credentials`) to unexpected origins when the `cors_origins` list contains a wildcard.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.