PatchSiren cyber security CVE debrief
CVE-2026-53629 glpi-project CVE debrief
CVE-2026-53629 is a SQL injection vulnerability in GLPI, a free asset and IT management software package. An attacker with READ right on logs can craft a URL for the history tab to inject attacker-controlled values into a database query. This issue affects versions from 9.4.0 until 10.0.26 and 11.0.8, and is fixed in versions 11.0.8 and 10.0.26. The vulnerability allows an attacker to inject malicious SQL code, potentially leading to data breaches or system compromise. Defenders should assess exposure and apply patches to mitigate this risk.
- Vendor
- glpi-project
- Product
- glpi
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Defenders responsible for GLPI deployments should assess exposure and apply patches. IT management teams and security personnel should verify version information and monitor logs for potential SQL injection attempts.
Why it matters
CVE-2026-53629 is a SQL injection vulnerability in GLPI that allows an attacker with READ right on logs to inject attacker-controlled values into a database query. Defenders should prioritize verifying exposure and applying patches for affected versions.
- Verify exposure and apply patches for GLPI versions 9.4.0 to 10.0.26 and 11.0.8
- Monitor logs for potential SQL injection attempts
- Assess and limit READ access to logs for sensitive information
Technical summary
The CVE-2026-53629 vulnerability affects GLPI versions from 9.4.0 until 10.0.26 and 11.0.8. An attacker with READ right on logs can inject attacker-controlled values into a database query through the history tab endpoint, permitting SQL injection. This vulnerability allows an attacker to inject malicious SQL code, potentially leading to data breaches or system compromise. Defenders should prioritize verifying exposure and applying patches for GLPI versions 9.4.0 to 10.0.26 and 11.0.8. The vulnerability has been publicly disclosed, and patches are available for affected versions.
Defensive priority
Defenders should prioritize verifying exposure and applying patches for GLPI versions 9.4.0 to 10.0.26 and 11.0.8.
Recommended defensive actions
- Verify GLPI version and check for exposure
- Apply patches for affected versions 9.4.0 to 10.0.26 and 11.0.8
- Monitor logs for potential SQL injection attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the SQL injection vulnerability in GLPI. The vendor has released patches for the affected versions. Evidence is limited to public CVE and NVD information. Defenders should verify GLPI version information and monitor logs for potential SQL injection attempts. The vulnerability has been publicly disclosed, and patches are available for affected versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-53629 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-53629
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-53629 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53629
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/glpi-project/glpi/commit/1296798fb03295d07c1d97fa8483d1dbab59fef5
-
Source reference
Unverified legacy reference
URL: https://github.com/glpi-project/glpi/commit/80b86c0dcad2f6ece9b5da445d1c264a1dda3ce5
-
Source reference
Unverified legacy reference
URL: https://github.com/glpi-project/glpi/releases/tag/10.0.26
-
Source reference
Unverified legacy reference
URL: https://github.com/glpi-project/glpi/releases/tag/11.0.8
-
Source reference
Unverified legacy reference
URL: https://github.com/glpi-project/glpi/security/advisories/GHSA-cpcj-x335-5cmh
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.