CRITICAL🇵🇱 Wersja polska

CVE-2026-26026

CVSS 9.1v3.1pub. 2026-04-06upd. 2026-04-07

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6.

🤖 AI Analysis
How it works

The vulnerability is classified as CWE-94 (Code Injection) and CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine) and consists of the fact that the template mechanism in GLPI does not properly neutralize malicious input data provided by an administrator. An attacker with administrator privileges can inject specially crafted expressions into the template engine, which will be executed on the server side as code. This leads to full remote code execution (RCE) on the server hosting the application.

Impact

An attacker can gain full control over the server — read, modify or delete data, execute arbitrary code, and potentially perform lateral movement within the internal network. Due to the high impact on confidentiality, integrity and availability (C:H/I:H/A:H) and changed scope (S:C), the consequences may extend beyond the GLPI instance itself.

Mitigation & patch

GLPI must be urgently updated to version 11.0.6, in which the vulnerability has been fixed. If an immediate update is not possible, it is recommended to restrict access to the administrative interface only to trusted networks and implement additional access control mechanisms (e.g., VPN, firewall).

Who is affected

GLPI in versions from 11.0.0 to 11.0.5 (before 11.0.6) of the Glpi-Project.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Glpi Project Glpi

    APP
    Glpi-Project
    11.0.0 – 11.0.6 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-35914CRITICAL9.8⚠ KEVPL ✓same product

PHP code injection w module htmlawed systemu GLPI

CVE-2024-50339CRITICAL9.3PL ✓same product

GLPI: Kradzież sesji przez nieuauthoryzowany dostęp do identyfikatorów sesji

CVE-2023-42802CRITICAL10.0PL ✓same product

GLPI: niezweryfikowana instancja obiektu umożliwia upload złośliwych plików PHP

CVE-2023-28838CRITICAL9.6PL ✓same product

SQL Injection w GLPI umożliwiający kradzież danych i zapis webshella

CVE-2023-28849CRITICAL10.0PL ✓same product

GLPI: SQL injection i XSS w endpoincie inwentaryzacji bez uwierzytelnienia