PatchSiren cyber security CVE debrief
CVE-2026-53626 glpi-project CVE debrief
CVE-2026-53626 is a vulnerability in GLPI, a free asset and IT management software package. From version 11.0.5 to 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. This issue allows a user to use an unrelated item that the user is permitted to view to read a document linked to an inaccessible item. The issue is fixed in version 11.0.8.
- Vendor
- glpi-project
- Product
- glpi
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Defenders and administrators using GLPI versions 11.0.5 to 11.0.7 should assess exposure and prioritize upgrading to version 11.0.8. This includes reviewing access controls, monitoring systems for exploitation attempts, and verifying exposure. Security teams and vulnerability management operators should also review the vulnerability details and plan for remediation.
Why it matters
CVE-2026-53626 is a high-severity vulnerability in GLPI that allows unauthorized access to documents due to flawed permission logic. Defenders should prioritize verifying exposure and upgrading to version 11.0.8.
- Potential unauthorized access to sensitive documents.
- Possible exploitation by users with legitimate access to unrelated items.
- Need for verification of GLPI version and exposure.
- Prioritization of upgrading to version 11.0.8.
Technical summary
The vulnerability in GLPI allows a user to access a document linked to an inaccessible item by using an unrelated item that the user is permitted to view. This is due to a flaw in the permission logic from version 11.0.5 to 11.0.8. The issue is addressed in version 11.0.8. Affected users should assess exposure and prioritize upgrading to version 11.0.8. The vulnerability has a high severity score and could lead to unauthorized access to sensitive documents if exploited. Defenders should review access controls and monitor systems for potential exploitation attempts.
Defensive priority
Defenders should prioritize verifying and upgrading to version 11.0.8 if using affected versions of GLPI.
Recommended defensive actions
- Verify and upgrade to version 11.0.8 if using affected versions of GLPI.
- Review and update access controls and permissions for GLPI users.
- Monitor GLPI systems for potential exploitation attempts.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and the fix in version 11.0.8. Defenders should verify exposure and review access controls. The vulnerability allows unauthorized access to documents due to flawed permission logic from version 11.0.5 to 11.0.8. Evidence is limited to public CVE details and NVD assessments.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-53626 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-53626
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-53626 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53626
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/glpi-project/glpi/commit/e984bf1ba435cee7319679df842c61b756baf191
-
Source reference
Unverified legacy reference
URL: https://github.com/glpi-project/glpi/releases/tag/11.0.8
-
Source reference
Unverified legacy reference
URL: https://github.com/glpi-project/glpi/security/advisories/GHSA-q9rc-v6vm-q5mm
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.