PatchSiren

glpi-project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM glpi-project CVE published 2026-09-25

CVE-2026-55217

A low-privileged authenticated user can create, update, or delete knowledge base comments and translations in GLPI versions 0.85 until 10.0.26 and 11.0.8 without required authorization. This issue is fixed in versions 11.0.8 and 10.0.26. The vulnerability allows unauthorized access to knowledge base features, potentially leading to data tampering or exposure. GLPI administrators should assess exposure and [truncated]

HIGH glpi-project CVE published 2026-09-25

CVE-2026-55214

CVE-2026-55214 is a high-severity vulnerability in GLPI, a free asset and IT management software package. An authenticated technician can store active markup in supplier website fields, triggering a cross-site scripting payload when another user opens the affected item's suppliers list. The issue is fixed in version 11.0.8. Defenders should assess exposure and apply the patch to prevent exploitation. The [truncated]

HIGH glpi-project CVE published 2026-09-25

CVE-2026-53629

CVE-2026-53629 is a SQL injection vulnerability in GLPI, a free asset and IT management software package. An attacker with READ right on logs can craft a URL for the history tab to inject attacker-controlled values into a database query. This issue affects versions from 9.4.0 until 10.0.26 and 11.0.8, and is fixed in versions 11.0.8 and 10.0.26. The vulnerability allows an attacker to inject malicious SQL [truncated]

MEDIUM glpi-project CVE published 2026-09-25

CVE-2026-53628

CVE-2026-53628 is a vulnerability in GLPI, a free asset and IT management software package. An administrator with specific rights can change the authentication method and disable two-factor authentication for user accounts outside their entity scope. The issue is fixed in versions 11.0.8 and 10.0.26. This vulnerability has a medium severity and defenders should assess exposure and prioritize patching. The [truncated]

MEDIUM glpi-project CVE published 2026-09-25

CVE-2026-53627

A low-privileged authenticated user can use the new API (v2) in GLPI versions 11.0.0 until 11.0.7 to perform update operations that the same user is normally forbidden to perform through the user interface due to inconsistent authorization checks in the API update flow. This issue is fixed in version 11.0.8. The vulnerability allows unauthorized updates, potentially leading to data tampering or corruption [truncated]

HIGH glpi-project CVE published 2026-09-25

CVE-2026-53626

CVE-2026-53626 is a vulnerability in GLPI, a free asset and IT management software package. From version 11.0.5 to 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. This issue allows a user to use an unrelated item that the user is permitted to view to read a document linked to an inaccessible item. The is [truncated]

HIGH glpi-project CVE published 2026-09-25

CVE-2026-53625

CVE-2026-53625 is a vulnerability in GLPI, a free asset and IT management software package. A technician can manipulate the authtype value through the API to change another user's authentication method. Under configurations using the legacy API REST interface or SSO logins, this can change a super-administrator's authentication method and enable account takeover. The issue is fixed in versions 11.0.8 and 10.0.26.

HIGH glpi-project CVE published 2026-09-25

CVE-2026-53610

A reflected cross-site scripting vulnerability exists in GLPI from version 11.0.0 to 11.0.7. An attacker can craft a URL for a dashboard that reflects attacker-controlled markup without sufficient output encoding. A user who opens the crafted URL triggers reflected cross-site scripting in the dashboard. This issue is fixed in version 11.0.8. The vulnerability allows an attacker to inject malicious scripts [truncated]

HIGH glpi-project CVE published 2026-09-25

CVE-2026-49470

CVE-2026-49470 is a vulnerability in GLPI, a free asset and IT management software package. The time-based one-time password verification endpoint does not limit failed submissions per user, allowing for brute-force compromise of the second factor and subsequent account takeover. This issue is fixed in version 11.0.8. Defenders should assess exposure, particularly for versions 11.0.0 through 11.0.7, and p [truncated]

MEDIUM glpi-project CVE published 2026-09-25

CVE-2026-49469

CVE-2026-49469 is a vulnerability in GLPI, a free asset and IT management software package. An authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP filter, allowing access to LDAP objects that the default filter was intended to exclude. This issue is fixed in versions 11.0.8 and 10.0.26.

CRITICAL glpi-project CVE published 2026-09-25

CVE-2026-48482

A critical vulnerability exists in GLPI, a free asset and IT management software package, from version 11.0.0 until 11.0.8. An administrator can exploit this issue by importing a crafted illustration or scene identifier, allowing a malicious script to be invoked remotely. The issue is fixed in version 11.0.8. This vulnerability requires immediate attention from administrators and security teams to assess [truncated]

HIGH glpi-project CVE published 2026-09-25

CVE-2026-47679

A vulnerability in GLPI, a free asset and IT management software package, allows any logged-in user to exploit insufficient path validation in the profile-picture update flow to request deletion of an attacker-selected file hosted by the server. This issue affects versions from 10.0.0 until 10.0.26 and 11.0.8, and is fixed in versions 11.0.8 and 10.0.26.

MEDIUM glpi-project CVE published 2026-09-25

CVE-2026-45801

An authenticated user without required permissions can enable debug mode in GLPI versions 0.72 to 10.0.26 and 11.0.8. This issue is fixed in versions 11.0.8 and 10.0.26. The vulnerability allows unauthorized access to debug mode, potentially leading to further exploitation. GLPI administrators should verify and apply patches to prevent exploitation. The issue is related to improper privilege management, a [truncated]

MEDIUM glpi-project CVE published 2026-06-28

CVE-2026-13490

CVE-2026-13490 is an authorization bypass vulnerability in the Document Handler component of glpi-project glpi versions 11.0.5, 11.0.6, and 11.0.7. The vulnerability exists in the `Document::canViewFile` function within the `front/document.send.php` file. An attacker can exploit this vulnerability remotely, but the attack has high complexity and is difficult to exploit. The vendor, glpi-project, was conta [truncated]

MEDIUM glpi-project CVE published 2026-05-19

CVE-2026-32312

CVE-2026-32312 is a medium-severity GLPI issue disclosed on 2026-05-19. In affected versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission could export the structure of forms they were not authorized to access. The issue is fixed in GLPI 11.0.7.