Unauthorized Form Structure Export in GLPI IT Management Software by GLPI Project
CVE-2026-32312

5.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
18 May 2026

What is CVE-2026-32312?

GLPI, a widely used IT management software, contains a vulnerability that allows authenticated users with READ permission to export the structure of forms they should not have access to. This flaw exists in versions 11.0.0 through 11.0.6 and poses a significant security risk as it could lead to the unauthorized exposure of sensitive organizational data. This issue has been resolved in version 11.0.7, which users are strongly encouraged to upgrade to in order to maintain the security of their systems.

Affected Version(s)

glpi >= 11.0.0, < 11.0.7

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.