LDAP Filter Bypass in GLPI IT Management Software
CVE-2026-49469

4.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-49469?

GLPI, a widely-used free asset and IT management software, is susceptible to a vulnerability that allows authenticated users such as hotliners or technicians to bypass the default LDAP filter through the user import feature. This exploitation can provide access to LDAP objects that should have been excluded by the predefined filter. It is crucial for users of versions 0.70 up to 10.0.26 and 11.0.8 to upgrade to the latest versions to ensure their systems are secure and protected against this issue.

Affected Version(s)

glpi >= 0.70, < 10.0.26 < 0.70, 10.0.26

glpi >= 11.0.0, < 11.0.8 < 11.0.0, 11.0.8

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.