VORANT. Threat Intelligence Sign in Get the full feed

GLPI patches multiple data-security flaws

medium vulnerability technology

ANSSI advises patching four vulnerabilities in GLPI IT asset management software that could allow data confidentiality/integrity breaches and security bypass.

The French national cybersecurity agency (ANSSI/CERT-FR) issued an advisory covering multiple vulnerabilities discovered in GLPI, an open-source IT asset and service management platform. The flaws affect GLPI versions 11.0.x prior to 11.0.8 and versions prior to 10.0.26, and could allow an attacker to compromise data confidentiality, data integrity, or bypass security policies.

Four CVEs (CVE-2026-45801, CVE-2026-53627, CVE-2026-53628, CVE-2026-55217) are referenced, corresponding to four separate GitHub security advisories published by the GLPI project on 21 July 2026. No indication of active exploitation is provided in the advisory; organizations running affected GLPI versions should apply the vendor-supplied patches referenced in the official security bulletins.

Mentioned in this report

Vulnerabilities CVE-2026-45801CVE-2026-53627CVE-2026-53628CVE-2026-55217

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0909

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free