GLPI vulnerable to unauthorized reading of a specific asset object
CVE-2026-44281
7HIGH
What is CVE-2026-44281?
GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user with config READ permission can read a specific asset object. Upgrade to 11.0.7 or 10.0.25 to receive a patch.
Affected Version(s)
glpi >= 11.0.0, < 11.0.7 < 11.0.0, 11.0.7
glpi >= 0.78, < 10.0.25 < 0.78, 10.0.25
