SQL Injection Vulnerability in GLPI Inventory Plugin by GPLI
CVE-2026-26001

7.1HIGH

Key Information:

Vendor
CVE Published:
17 March 2026

What is CVE-2026-26001?

The GLPI Inventory Plugin, which facilitates network discovery, inventory management, software deployment, and data collection for GLPI agents, contains a vulnerability that allows for SQL injection. This occurs due to insufficient sanitization of user input when generating reports, potentially allowing users with adequate permissions to execute malicious SQL commands. This vulnerability has been addressed in version 1.6.6, emphasizing the importance of updating to secure user data and system integrity.

Affected Version(s)

glpi-inventory-plugin < 1.6.6

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.