GLPI patches multiple flaws in latest advisory
Multiple vulnerabilities in GLPI IT asset management software allow privilege escalation, SQL injection, and data integrity attacks.
ANSSI (CERT-FR) has published an advisory covering multiple vulnerabilities discovered in GLPI, an open-source IT asset and service management platform. The flaws affect GLPI versions 11.0.x prior to 11.0.8 and all versions prior to 10.0.26. The vulnerabilities span several classes including privilege escalation, data integrity compromise, security policy bypass, indirect remote code injection (XSS), and SQL injection (SQLi).
Eight distinct GitHub security advisories were published by the GLPI project on 27 July 2026, correlating to eight CVE identifiers. No public exploitation has been reported at this time; this is a standard vendor patch disclosure. Organizations running affected GLPI versions should apply the vendor-supplied patches referenced in the official security bulletins as soon as practicable.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0935
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free