#VU125064 Improper Authentication in GLPI - CVE-2026-25937
Published: April 7, 2026
GLPI
glpi-project
Description
The vulnerability allows a remote user to bypass multi-factor authentication and compromise a user account.
The vulnerability exists due to improper authentication in the multi-factor authentication mechanism when processing login requests. A remote privileged user can use known user credentials to bypass multi-factor authentication and compromise a user account.