CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-46606

highCVSS 7.8covered by 1 sourcefirst seen 2026-06-22
Summary The Glances KVM/QEMU monitoring engine (glances/plugins/vms/engines/virsh.py) passes VM domain names, read directly from virsh list --all output, into f-string command templates that are processed by secure_popen(). secure_popen() is explicitly designed to interpret &&, |, and > as shell operators. Because domain names are never sanitised before interpolation, any user with the ability to create or rename a KVM/QEMU virtual machine can execute arbitrary commands as the OS user running Glances — commonly root on hypervisor hosts. Details Affected file: glances/plugins/vms/engines/virsh.py Direct URLs (commit 04579778e733d705898a169e049dc84772c852da): - https://github.com/nicolargo/glances/blob/04579778e733d705898a169e049dc84772c852da/glances/plugins/vms/engines/virsh.py#L185 - https://github.com/nicolargo/glances/blob/04579778e733d705898a169e049dc84772c852da/glances/plugins/vms/engines/virsh.py#L204 The vulnerable calls are on lines 185 and 204: line 185 (update_stats) ret_cmd = secure_popen(f'{VIRSH_PATH} {VIRSH_DOMAIN_STATS_OPTIONS} {domain}') line 204 (update_title) ret_cmd = secure_popen(f'{VIRSH_PATH} {VIRSH_DOMAIN_TITLE_OPTIONS} {domain}') domain is the name string parsed from the output of virsh list --all (line 59–78 in the same file); no sanitisation is applied to it at any point before it reaches secure_popen(). secure_popen() is defined in glances/secure.py. It explicitly splits the command string on &&, |, and > before invoking subprocess.Popen with shell=False on each part, meaning all three operators are treated as real pipeline/redirection control characters: glances/secure.py def secure_popen(cmd): ret = '' for c in cmd.split('&&'): # '&&' → two separate processes ret += __secure_popen(c) return ret def __secure_popen(cmd): for sub_cmd in cmd.split('|'): # '|' → stdin/stdout piped p = Popen(sub_cmd_split, shell=False, stdin=sub_cmd_stdin, stdout=PIPE, stderr=PIPE) '>' is split separately for file redirection By contrast, actions.

⚡ Watch CVE-2026-46606

Get an email if CVE-2026-46606 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-46606

CVE.org record

Embed the live status

CVE-2026-46606 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-46606 status](https://www.csirts.com/badge/CVE-2026-46606)](https://www.csirts.com/cve/CVE-2026-46606)