Multiple vulnerabilities in GLPI IT asset management software allow attackers to…
Multiple vulnerabilities in GLPI IT asset management software allow attackers to compromise data integrity, execute XSS attacks, and bypass security policies.
French CERT has disclosed multiple security vulnerabilities affecting GLPI, an open-source IT asset management and helpdesk solution. The vulnerabilities impact GLPI versions prior to 10.0.25 and versions 11.0.x prior to 11.0.7. The flaws enable attackers to compromise data integrity, perform cross-site scripting (XSS) attacks for remote code injection, and bypass implemented security policies.
Nine separate GitHub security advisories were published on June 1, 2026, detailing the vulnerabilities, which have been assigned four CVE identifiers. The vendor has released patches in versions 10.0.25 and 11.0.7 to address these issues. Organizations running GLPI should prioritize updating to the patched versions to mitigate exploitation risks.
Given GLPI's widespread use in IT service management across various sectors, these vulnerabilities pose significant risks to organizations relying on the platform for asset tracking and helpdesk operations. The combination of XSS and security policy bypass capabilities could allow attackers to escalate privileges or compromise user sessions.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0675
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free