SQL Injection Vulnerability in GLPI Inventory Plugin by GPLI
CVE-2026-26001
7.1HIGH
What is CVE-2026-26001?
The GLPI Inventory Plugin, which facilitates network discovery, inventory management, software deployment, and data collection for GLPI agents, contains a vulnerability that allows for SQL injection. This occurs due to insufficient sanitization of user input when generating reports, potentially allowing users with adequate permissions to execute malicious SQL commands. This vulnerability has been addressed in version 1.6.6, emphasizing the importance of updating to secure user data and system integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
glpi-inventory-plugin < 1.6.6
