Vulnerability
CVE-2026-55217
Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.
- Sharing
- PUBLIC-OSINT
- Confidence
- 100
- Source
- The CVE Program
- Updated
- 26/09/2026 04:49
Description
GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete knowledge base comments and translations without the required authorization for the affected content. This issue is fixed in versions 11.0.8 and 10.0.26.
Aliases and classifications
CWE-285Improper Authorization
Minimised technical details
No raw data- cisa kev
- False
Provenance
Public references
- https://github.com/glpi-project/glpi/commit/1cbf69b99dfd0610f1c03a3f245f3b248e1bfde0
https://github.com/glpi-project/glpi/commit/1cbf69b99dfd0610f1c03a3f245f3b248e1bfde0 - https://github.com/glpi-project/glpi/releases/tag/11.0.8
https://github.com/glpi-project/glpi/releases/tag/11.0.8 - https://github.com/glpi-project/glpi/releases/tag/10.0.26
https://github.com/glpi-project/glpi/releases/tag/10.0.26 - https://github.com/glpi-project/glpi/commit/9c29f25bd09eca9e62ca50c52b3ebd15b02997b2
https://github.com/glpi-project/glpi/commit/9c29f25bd09eca9e62ca50c52b3ebd15b02997b2 - https://github.com/glpi-project/glpi/security/advisories/GHSA-xm3v-3g6q-g9q8
https://github.com/glpi-project/glpi/security/advisories/GHSA-xm3v-3g6q-g9q8
EudorIA correlation
Intel catalogue
The vulnerability is also available in the EudorIA editorial catalogue.
Open EudorIA analysisPresence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.