PT-2026-30610 · Glpi+1 · Glpi+1

Aarjubh

+1

·

Published

2026-04-06

·

Updated

2026-04-17

·

CVE-2026-26263

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GLPI versions 11.0.0 through 11.0.5
Description An unauthenticated time-based blind SQL injection exists in the Search engine. SQL injection is a flaw that allows an attacker to interfere with the queries that an application makes to its database, potentially allowing them to view or modify data they are not authorized to access.
Recommendations Update to version 11.0.6.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07155
CVE-2026-26263

Affected Products

Glpi
Red Os