Data Exposure Vulnerability in GLPI IT Management Software by GLPI Project
CVE-2026-44281
7HIGH
What is CVE-2026-44281?
GLPI, an open-source asset and IT management software, is susceptible to a data exposure issue where authenticated users with 'config READ' permission can access sensitive asset objects. This vulnerability affects users of versions 0.78 and prior to 10.0.25 and 11.0.7. To mitigate the risk, it is recommended to upgrade to version 11.0.7 or 10.0.25 where the issue has been resolved. For more details and guidance on securing your systems, please refer to the advisory.
Affected Version(s)
glpi >= 11.0.0, < 11.0.7 < 11.0.0, 11.0.7
glpi >= 0.78, < 10.0.25 < 0.78, 10.0.25
