SB20261007226 - Multiple vulnerabilities in GLPI
Published: October 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to perform cross-site scripting attacks.
The vulnerability exists due to improper neutralization of input during web page generation in the form illustration import feature when processing imported form data. A remote privileged user can inject arbitrary content into a form's custom illustration via a JSON import to perform cross-site scripting attacks.
Exploitation requires form import permissions.
2) Improper access control (CVE-ID: N/A)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in template-generated followups, tasks, and solutions when handling access to these items. A remote user can access followups, tasks, and solutions generated from templates to disclose sensitive information.
Exposure of information from tickets, problems, or changes depends on the templates configuration.
Remediation
Install update from vendor's website.