File Upload Vulnerability in GLPI IT Management Software
CVE-2026-22248
8.1HIGH
What is CVE-2026-22248?
GLPI, an open-source asset and IT management software, is prone to a file upload vulnerability. Users with technician-level authentication can upload malicious files that get executed through an unsafe PHP instantiation. This security flaw is present in versions 11.0.0 to prior to 11.0.5, making it crucial for users to upgrade to the latest version to mitigate risks. For more information, refer to the security advisory.
Affected Version(s)
glpi >= 11.0.0, < 11.0.5
