What is CVE-2026-68518?
CVE-2026-68518 is a vulnerability in the Glances open-source monitoring tool prior to version 4.5.6. The flaw in _sanitize allows adjacent Mustache variables to reconstruct shell operators, potentially leading to arbitrary code execution via secure_popen(). Users should update to version 4.5.6 or later immediately.
Azərbaycanca: CVE-2026-68518: Glances açıq mənbəli monitorinq alətində 4.5.6 versiyasından əvvəl _sanitize funksiyasındakı qüsurdur. Bu, bitişik Mustache dəyişənlərinin shell əmrlərini yenidən qurmasına imkan verərək secure_popen() vasitəsilə ixtiyari kod icrasına yol aça bilər. İstifadəçilər dərhal 4.5.6 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of the Glances tool are affected by CVE-2026-68518?
This vulnerability affects all versions of Glances prior to 4.5.6. To address the issue, users must update to at least version 4.5.6.
What security impact can result from successfully exploiting CVE-2026-68518?
Successful exploitation of this flaw can lead to arbitrary code execution via the secure_popen() function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.