SB20261007226 - Multiple vulnerabilities in GLPI



SB20261007226 - Multiple vulnerabilities in GLPI

Published: October 7, 2026

Security Bulletin ID SB20261007226
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to perform cross-site scripting attacks.

The vulnerability exists due to improper neutralization of input during web page generation in the form illustration import feature when processing imported form data. A remote privileged user can inject arbitrary content into a form's custom illustration via a JSON import to perform cross-site scripting attacks.

Exploitation requires form import permissions.


2) Improper access control (CVE-ID: N/A)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in template-generated followups, tasks, and solutions when handling access to these items. A remote user can access followups, tasks, and solutions generated from templates to disclose sensitive information.

Exposure of information from tickets, problems, or changes depends on the templates configuration.


Remediation

Install update from vendor's website.