Data Exposure Vulnerability in GLPI IT Management Software by GLPI Project
CVE-2026-44281

7HIGH

Key Information:

Status
Vendor
CVE Published:
3 June 2026

What is CVE-2026-44281?

GLPI, an open-source asset and IT management software, is susceptible to a data exposure issue where authenticated users with 'config READ' permission can access sensitive asset objects. This vulnerability affects users of versions 0.78 and prior to 10.0.25 and 11.0.7. To mitigate the risk, it is recommended to upgrade to version 11.0.7 or 10.0.25 where the issue has been resolved. For more details and guidance on securing your systems, please refer to the advisory.

Affected Version(s)

glpi >= 11.0.0, < 11.0.7 < 11.0.0, 11.0.7

glpi >= 0.78, < 10.0.25 < 0.78, 10.0.25

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.