Unauthorized Form Structure Export in GLPI IT Management Software by GLPI Project
CVE-2026-32312
5.1MEDIUM
What is CVE-2026-32312?
GLPI, a widely used IT management software, contains a vulnerability that allows authenticated users with READ permission to export the structure of forms they should not have access to. This flaw exists in versions 11.0.0 through 11.0.6 and poses a significant security risk as it could lead to the unauthorized exposure of sensitive organizational data. This issue has been resolved in version 11.0.7, which users are strongly encouraged to upgrade to in order to maintain the security of their systems.
Affected Version(s)
glpi >= 11.0.0, < 11.0.7
