File Read Vulnerability in GLPI IT Management Software by GLPI Project
CVE-2026-42320

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 June 2026

What is CVE-2026-42320?

A file read vulnerability in GLPI, a widely used asset and IT management software, allows unauthorized technicians to access arbitrary files from the GLPI_DOC_DIR. This issue affects versions from 0.50 up to 10.0.24 and 11.0.6, exposing sensitive data. Users are advised to upgrade to versions 10.0.25 or 11.0.7 to mitigate this risk.

Affected Version(s)

glpi >= 11.0.0, < 11.0.7 < 11.0.0, 11.0.7

glpi >= 0.50, < 10.0.25 < 0.50, 10.0.25

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.