Template Injection Vulnerability in GLPI IT Management Software
CVE-2026-26026
9.1CRITICAL
Key Information:
- Vendor
GLPI Project
- Status
- Vendor
- CVE Published:
- 6 April 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-26026?
GLPI, an open-source asset and IT management software, is susceptible to template injection through administrator actions, allowing for remote code execution. This vulnerability affects versions 11.0.0 to 11.0.5 and has been resolved in version 11.0.6. Users of affected versions are advised to update to the latest version to mitigate the risk of exploitation.
Affected Version(s)
glpi >= 11.0.0, < 11.0.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
