SQL Injection Vulnerability in GLPI Inventory Plugin by GPLI
CVE-2026-26001
7.1HIGH
What is CVE-2026-26001?
The GLPI Inventory Plugin, which facilitates network discovery, inventory management, software deployment, and data collection for GLPI agents, contains a vulnerability that allows for SQL injection. This occurs due to insufficient sanitization of user input when generating reports, potentially allowing users with adequate permissions to execute malicious SQL commands. This vulnerability has been addressed in version 1.6.6, emphasizing the importance of updating to secure user data and system integrity.
Affected Version(s)
glpi-inventory-plugin < 1.6.6
