Authentication Manipulation Vulnerability in GLPI IT Management Software
CVE-2026-53625

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-53625?

The vulnerability impacts GLPI, a widely-used asset and IT management software. Versions from 0.70 up to 10.0.26 and 11.0.8 contain a flaw in the API that allows technicians to manipulate the 'authtype' parameter. This manipulation can result in unauthorized changes to users' authentication methods, including super-administrators, leading to potential account takeovers. This issue arises particularly in setups using legacy API REST interfaces or SSO logins. The vulnerability has been addressed in GLPI versions 11.0.8 and 10.0.26, ensuring enhanced security and protection for users.

Affected Version(s)

glpi >= 0.70, < 10.0.26 < 0.70, 10.0.26

glpi >= 11.0.0, < 11.0.8 < 11.0.0, 11.0.8

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.