PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-53628 glpi-project CVE debrief

CVE-2026-53628 is a vulnerability in GLPI, a free asset and IT management software package. An administrator with specific rights can change the authentication method and disable two-factor authentication for user accounts outside their entity scope. The issue is fixed in versions 11.0.8 and 10.0.26. This vulnerability has a medium severity and defenders should assess exposure and prioritize patching. The affected user-account administration flow did not consistently enforce the target user's entity-scoped update permission, allowing for potential unauthorized access and elevation of privileges.

Vendor
glpi-project
Product
glpi
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Defenders responsible for GLPI installations, administrators with Update auth and sync or Update auth, sync and 2FA rights, and teams managing user account administration should assess exposure and prioritize patching.

Why it matters

CVE-2026-53628 is a medium-severity vulnerability in GLPI that allows administrators with specific rights to change authentication methods and disable two-factor authentication for user accounts outside their entity scope. Defenders should prioritize verifying affected versions, applying patches, and reviewing administrator permissions and two-factor authentication settings.

  • Potential unauthorized access to user accounts
  • Elevation of privileges for administrators with specific rights
  • Bypass of two-factor authentication
  • Increased risk of lateral movement within the affected entity

Technical summary

The affected user-account administration flow in GLPI did not consistently enforce the target user's entity-scoped update permission, allowing administrators with specific rights to change the authentication method and disable two-factor authentication for user accounts outside their entity scope. This issue allows for potential unauthorized access and elevation of privileges. The vulnerability is fixed in versions 11.0.8 and 10.0.26, and defenders should prioritize verifying affected versions and applying patches.

Defensive priority

Defenders should prioritize verifying affected versions and applying patches, as well as reviewing administrator permissions and two-factor authentication settings.

Recommended defensive actions

  • Verify affected versions and apply patches
  • Review administrator permissions and two-factor authentication settings
  • Monitor user account administration flows for potential abuse
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, affected versions, and fixed versions. However, additional information on exploitation or victim impact is not available. The vulnerability affects GLPI versions from 0.84 until 10.0.26 and 11.0.8. Defenders should verify affected versions, apply patches, and review administrator permissions and two-factor authentication settings. The CVE Program and NVD entries are official sources for this vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-53628 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-53628

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-53628 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53628

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.