# GLPI patches multiple flaws in latest advisory

Published: 2026-07-27 · Severity: medium
Canonical: https://vorant.io/reports/e051c447-450f-59e3-a797-b733c3593d22/glpi-patches-multiple-flaws-in-latest-advisory

> Multiple vulnerabilities in GLPI IT asset management software allow privilege escalation, SQL injection, and data integrity attacks.

ANSSI (CERT-FR) has published an advisory covering multiple vulnerabilities discovered in GLPI, an open-source IT asset and service management platform. The flaws affect GLPI versions 11.0.x prior to 11.0.8 and all versions prior to 10.0.26. The vulnerabilities span several classes including privilege escalation, data integrity compromise, security policy bypass, indirect remote code injection (XSS), and SQL injection (SQLi).

Eight distinct GitHub security advisories were published by the GLPI project on 27 July 2026, correlating to eight CVE identifiers. No public exploitation has been reported at this time; this is a standard vendor patch disclosure. Organizations running affected GLPI versions should apply the vendor-supplied patches referenced in the official security bulletins as soon as practicable.

## Mentioned in this report

- Vulnerabilities: CVE-2026-47678, CVE-2026-47679, CVE-2026-52848, CVE-2026-53610, CVE-2026-53625, CVE-2026-53629, CVE-2026-55214, CVE-2026-57152

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0935

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e051c447-450f-59e3-a797-b733c3593d22/glpi-patches-multiple-flaws-in-latest-advisory.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
