PT-2026-25929 · Glpi+1 · Glpi+1

Login-Securite

·

Published

2026-03-17

·

Updated

2026-05-24

·

CVE-2026-25936

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GLPI versions 11.0.0 through 11.0.5
Description GLPI is a free Asset and IT management software package. An authenticated user can perform a SQL injection. The SQL injection can be performed through unspecified vectors.
Recommendations Update to version 11.0.6 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-25936
GHSA-QW3X-7VV2-7759

Affected Products

Glpi
Red Os