SB20260721151 - Multiple vulnerabilities in GLPI



SB20260721151 - Multiple vulnerabilities in GLPI

Published: July 21, 2026

Security Bulletin ID SB20260721151
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 vulnerabilities.


1) Improper access control (CVE-ID: CVE-2026-53627)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to perform unauthorized update operations.

The vulnerability exists due to improper access control in the API v2 when handling update requests. A remote user can send crafted API requests to perform unauthorized update operations.

The issue affects operations that are forbidden to low-privilege users through the user interface.


2) Improper privilege management (CVE-ID: CVE-2026-45801)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to enable debug mode without authorization.

The vulnerability exists due to improper privilege management in the debug mode functionality when handling requests to enable debug mode. A remote user can send a request to enable debug mode to enable debug mode without authorization.


3) Improper Authorization (CVE-ID: CVE-2026-53628)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to modify users' authentication methods and disable two-factor authentication outside the intended entity scope.

The vulnerability exists due to improper authorization in the authentication method update functionality when handling administrative updates to user authentication settings. A remote privileged user can change authentication methods for users outside their entity scope to modify users' authentication methods and disable two-factor authentication outside the intended entity scope.

Exploitation requires the "Update auth and sync" or "Update auth, sync and 2FA" right.


4) Improper Authorization (CVE-ID: CVE-2026-55217)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to modify knowledge base comments and translations.

The vulnerability exists due to improper authorization in knowledge base comments and translations handling when handling requests. A remote user can create, update, or delete knowledge base comments and translations to modify knowledge base comments and translations.


5) LDAP injection (CVE-ID: CVE-2026-49469)

CWE-ID: CWE-90 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to access unexpected objects on the LDAP server.

The vulnerability exists due to improper neutralization of special elements used in an LDAP query in the user import feature when processing LDAP filter input. A remote privileged user can supply a crafted LDAP filter to access unexpected objects on the LDAP server.

The issue allows bypass of the default LDAP filter.


Remediation

Install update from vendor's website.