PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-53626 glpi-project CVE debrief

CVE-2026-53626 is a vulnerability in GLPI, a free asset and IT management software package. From version 11.0.5 to 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. This issue allows a user to use an unrelated item that the user is permitted to view to read a document linked to an inaccessible item. The issue is fixed in version 11.0.8.

Vendor
glpi-project
Product
glpi
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Defenders and administrators using GLPI versions 11.0.5 to 11.0.7 should assess exposure and prioritize upgrading to version 11.0.8. This includes reviewing access controls, monitoring systems for exploitation attempts, and verifying exposure. Security teams and vulnerability management operators should also review the vulnerability details and plan for remediation.

Why it matters

CVE-2026-53626 is a high-severity vulnerability in GLPI that allows unauthorized access to documents due to flawed permission logic. Defenders should prioritize verifying exposure and upgrading to version 11.0.8.

  • Potential unauthorized access to sensitive documents.
  • Possible exploitation by users with legitimate access to unrelated items.
  • Need for verification of GLPI version and exposure.
  • Prioritization of upgrading to version 11.0.8.

Technical summary

The vulnerability in GLPI allows a user to access a document linked to an inaccessible item by using an unrelated item that the user is permitted to view. This is due to a flaw in the permission logic from version 11.0.5 to 11.0.8. The issue is addressed in version 11.0.8. Affected users should assess exposure and prioritize upgrading to version 11.0.8. The vulnerability has a high severity score and could lead to unauthorized access to sensitive documents if exploited. Defenders should review access controls and monitor systems for potential exploitation attempts.

Defensive priority

Defenders should prioritize verifying and upgrading to version 11.0.8 if using affected versions of GLPI.

Recommended defensive actions

  • Verify and upgrade to version 11.0.8 if using affected versions of GLPI.
  • Review and update access controls and permissions for GLPI users.
  • Monitor GLPI systems for potential exploitation attempts.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its impact, and the fix in version 11.0.8. Defenders should verify exposure and review access controls. The vulnerability allows unauthorized access to documents due to flawed permission logic from version 11.0.5 to 11.0.8. Evidence is limited to public CVE details and NVD assessments.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-53626 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-53626

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-53626 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53626

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.