SQL injection in GLPI Inventory plugin - CVE-2026-26001
Published: April 27, 2026
GLPI Inventory plugin
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information and modify data.
The vulnerability exists due to improper neutralization of special elements used in an SQL command in the dropdown_calendar report when processing user-supplied report input. A remote user can send a specially crafted report parameter to disclose sensitive information and modify data.