Vulnerability
CVE-2026-53629
Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.
- Sharing
- PUBLIC-OSINT
- Confidence
- 100
- Source
- The CVE Program
- Updated
- 26/09/2026 03:02
Description
GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL for the history tab that injects attacker-controlled values into a database query. This permits SQL injection through the history tab endpoint. This issue is fixed in versions 11.0.8 and 10.0.26.
Aliases and classifications
CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Minimised technical details
No raw data- cisa kev
- False
Provenance
Public references
- https://github.com/glpi-project/glpi/security/advisories/GHSA-cpcj-x335-5cmh
https://github.com/glpi-project/glpi/security/advisories/GHSA-cpcj-x335-5cmh - https://github.com/glpi-project/glpi/commit/80b86c0dcad2f6ece9b5da445d1c264a1dda3ce5
https://github.com/glpi-project/glpi/commit/80b86c0dcad2f6ece9b5da445d1c264a1dda3ce5 - https://github.com/glpi-project/glpi/releases/tag/11.0.8
https://github.com/glpi-project/glpi/releases/tag/11.0.8 - https://github.com/glpi-project/glpi/releases/tag/10.0.26
https://github.com/glpi-project/glpi/releases/tag/10.0.26 - https://github.com/glpi-project/glpi/commit/1296798fb03295d07c1d97fa8483d1dbab59fef5
https://github.com/glpi-project/glpi/commit/1296798fb03295d07c1d97fa8483d1dbab59fef5
EudorIA correlation
Intel catalogue
The vulnerability is also available in the EudorIA editorial catalogue.
Open EudorIA analysisPresence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.