Authentication Bypass in GLPI IT Management Software
CVE-2026-53628
5.9MEDIUM
What is CVE-2026-53628?
A security issue in GLPI allows administrators with specific permissions to modify authentication methods for user accounts that fall outside their designated entity scope. This vulnerability arises during the user-account administration process, wherein necessary checks for entity-scoped update permissions are inconsistently enforced. As a result, an administrator might disable two-factor authentication for other users, potentially exposing sensitive accounts to unauthorized access. The flaw has been addressed in GLPI versions 11.0.8 and 10.0.26.
Affected Version(s)
glpi >= 0.84, < 10.0.26 < 0.84, 10.0.26
glpi >= 11.0.0, < 11.0.8 < 11.0.0, 11.0.8
