Access Control Vulnerability in GLPI Asset Management Software by GLPI Project
CVE-2026-42318

7HIGH

Key Information:

Status
Vendor
CVE Published:
3 June 2026

What is CVE-2026-42318?

GLPI, a widely used free asset and IT management software, has a vulnerability that allows low privilege users with access to planning features to delete any object within the system. This issue affects versions of GLPI from 9.5.0 up to, but not including, 10.0.25 and 11.0.7. To mitigate this vulnerability, users are encouraged to upgrade to the latest versions or, as an immediate workaround, disable the delete permissions for planning users.

Affected Version(s)

glpi >= 11.0.0, < 11.0.7 < 11.0.0, 11.0.7

glpi >= 9.5.0, < 10.0.25 < 9.5.0, 10.0.25

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.