Vulnerabilità
CVE-2026-55217
Scheda descrittiva ricevuta da OpenCTI e minimizzata per la consultazione nel portale Intel.
- Condivisione
- PUBLIC-OSINT
- Confidenza
- 100
- Fonte
- The CVE Program
- Aggiornata
- 26/09/2026 04:49
Descrizione
GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete knowledge base comments and translations without the required authorization for the affected content. This issue is fixed in versions 11.0.8 and 10.0.26.
Alias e classificazioni
CWE-285Improper Authorization
Dettagli tecnici minimizzati
Nessun dato grezzo- cisa kev
- False
Provenienza
Riferimenti pubblici
- https://github.com/glpi-project/glpi/commit/1cbf69b99dfd0610f1c03a3f245f3b248e1bfde0
https://github.com/glpi-project/glpi/commit/1cbf69b99dfd0610f1c03a3f245f3b248e1bfde0 - https://github.com/glpi-project/glpi/releases/tag/11.0.8
https://github.com/glpi-project/glpi/releases/tag/11.0.8 - https://github.com/glpi-project/glpi/releases/tag/10.0.26
https://github.com/glpi-project/glpi/releases/tag/10.0.26 - https://github.com/glpi-project/glpi/commit/9c29f25bd09eca9e62ca50c52b3ebd15b02997b2
https://github.com/glpi-project/glpi/commit/9c29f25bd09eca9e62ca50c52b3ebd15b02997b2 - https://github.com/glpi-project/glpi/security/advisories/GHSA-xm3v-3g6q-g9q8
https://github.com/glpi-project/glpi/security/advisories/GHSA-xm3v-3g6q-g9q8
Correlazione EudorIA
Catalogo Intel
La vulnerabilità è presente anche nel catalogo editoriale EudorIA.
Apri analisi EudorIALa presenza in OpenCTI descrive una correlazione di intelligence e non costituisce, da sola, prova di compromissione, attribuzione legale o indicazione operativa applicabile senza verifica del contesto.