What is CVE-2026-68520?
CVE-2026-68520 is a vulnerability in the open-source Glances monitoring tool prior to version 4.5.6. It allows unauthenticated exposure of 'public_username' and credentials embedded in 'public_api' values via GET requests to /api/4/config endpoints. Users must upgrade to version 4.5.6 or later immediately.
Azərbaycanca: CVE-2026-68520, açıq mənbəli Glances monitorinq alətinin 4.5.6 versiyasından əvvəlki versiyalarında aşkarlanan boşluqdur. Bu boşluq autentifikasiya olunmamış GET sorğuları vasitəsilə 'public_api' daxilindəki 'public_username' və digər etimad məlumatlarının ifşa olunmasına səbəb olur. Glances istifadəçiləri dərhal 4.5.6 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of Glances are affected by CVE-2026-68520?
Versions of the Glances monitoring tool prior to 4.5.6 are affected by this vulnerability.
What kind of data can be exposed through CVE-2026-68520?
This vulnerability can lead to unauthenticated exposure of 'public_username' and other credentials embedded in 'public_api' values via GET requests.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.