VORANT. Threat Intelligence Sign in Get the full feed

GLPI patches multiple flaws in latest advisory

medium vulnerability

Multiple vulnerabilities in GLPI IT asset management software allow privilege escalation, SQL injection, and data integrity attacks.

ANSSI (CERT-FR) has published an advisory covering multiple vulnerabilities discovered in GLPI, an open-source IT asset and service management platform. The flaws affect GLPI versions 11.0.x prior to 11.0.8 and all versions prior to 10.0.26. The vulnerabilities span several classes including privilege escalation, data integrity compromise, security policy bypass, indirect remote code injection (XSS), and SQL injection (SQLi).

Eight distinct GitHub security advisories were published by the GLPI project on 27 July 2026, correlating to eight CVE identifiers. No public exploitation has been reported at this time; this is a standard vendor patch disclosure. Organizations running affected GLPI versions should apply the vendor-supplied patches referenced in the official security bulletins as soon as practicable.

Mentioned in this report

Vulnerabilities CVE-2026-47678CVE-2026-47679CVE-2026-52848CVE-2026-53610CVE-2026-53625CVE-2026-53629CVE-2026-55214CVE-2026-57152

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0935

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free