PT-2026-30608 · Glpi · Glpi

Published

2026-04-06

·

Updated

2026-04-06

·

CVE-2026-26026

CVSS v3.1

9.1

Critical

AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
🚨 CVE-2026-26026: GLPI...
Admin-to-RCE via double template compilation in GLPI 11.0.0-11.0.5 - classic Twig injection with a twist that bypasses standard filters #SSTI #RCE.
#netsec #vulnerability #CVE #sysadmin #zeroday

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-26026

Affected Products

Glpi