Vulnerability
CVE-2026-47679
Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.
- Sharing
- PUBLIC-OSINT
- Confidence
- 100
- Source
- The CVE Program
- Updated
- 26/09/2026 04:22
Description
GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path validation in the profile-picture update flow to request deletion of an attacker-selected file hosted by the server. This issue is fixed in versions 11.0.8 and 10.0.26.
Aliases and classifications
CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Minimised technical details
No raw data- cisa kev
- False
Provenance
Public references
- https://github.com/glpi-project/glpi/commit/78ec583051bac3c1b3f9d21729c55cac62afa2f3
https://github.com/glpi-project/glpi/commit/78ec583051bac3c1b3f9d21729c55cac62afa2f3 - https://github.com/glpi-project/glpi/commit/54306faf6a724321ba82c53c7c07ff6612a0d832
https://github.com/glpi-project/glpi/commit/54306faf6a724321ba82c53c7c07ff6612a0d832 - https://github.com/glpi-project/glpi/security/advisories/GHSA-x5r8-r6vj-79cw
https://github.com/glpi-project/glpi/security/advisories/GHSA-x5r8-r6vj-79cw - https://github.com/glpi-project/glpi/releases/tag/11.0.8
https://github.com/glpi-project/glpi/releases/tag/11.0.8 - https://github.com/glpi-project/glpi/releases/tag/10.0.26
https://github.com/glpi-project/glpi/releases/tag/10.0.26
EudorIA correlation
Intel catalogue
The vulnerability is also available in the EudorIA editorial catalogue.
Open EudorIA analysisPresence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.