PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-53629 glpi-project CVE debrief

CVE-2026-53629 is a SQL injection vulnerability in GLPI, a free asset and IT management software package. An attacker with READ right on logs can craft a URL for the history tab to inject attacker-controlled values into a database query. This issue affects versions from 9.4.0 until 10.0.26 and 11.0.8, and is fixed in versions 11.0.8 and 10.0.26. The vulnerability allows an attacker to inject malicious SQL code, potentially leading to data breaches or system compromise. Defenders should assess exposure and apply patches to mitigate this risk.

Vendor
glpi-project
Product
glpi
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Defenders responsible for GLPI deployments should assess exposure and apply patches. IT management teams and security personnel should verify version information and monitor logs for potential SQL injection attempts.

Why it matters

CVE-2026-53629 is a SQL injection vulnerability in GLPI that allows an attacker with READ right on logs to inject attacker-controlled values into a database query. Defenders should prioritize verifying exposure and applying patches for affected versions.

  • Verify exposure and apply patches for GLPI versions 9.4.0 to 10.0.26 and 11.0.8
  • Monitor logs for potential SQL injection attempts
  • Assess and limit READ access to logs for sensitive information

Technical summary

The CVE-2026-53629 vulnerability affects GLPI versions from 9.4.0 until 10.0.26 and 11.0.8. An attacker with READ right on logs can inject attacker-controlled values into a database query through the history tab endpoint, permitting SQL injection. This vulnerability allows an attacker to inject malicious SQL code, potentially leading to data breaches or system compromise. Defenders should prioritize verifying exposure and applying patches for GLPI versions 9.4.0 to 10.0.26 and 11.0.8. The vulnerability has been publicly disclosed, and patches are available for affected versions.

Defensive priority

Defenders should prioritize verifying exposure and applying patches for GLPI versions 9.4.0 to 10.0.26 and 11.0.8.

Recommended defensive actions

  • Verify GLPI version and check for exposure
  • Apply patches for affected versions 9.4.0 to 10.0.26 and 11.0.8
  • Monitor logs for potential SQL injection attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the SQL injection vulnerability in GLPI. The vendor has released patches for the affected versions. Evidence is limited to public CVE and NVD information. Defenders should verify GLPI version information and monitor logs for potential SQL injection attempts. The vulnerability has been publicly disclosed, and patches are available for affected versions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-53629 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-53629

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-53629 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53629

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.