Incorrect Comparison in GLPI - #VU133154
Published: June 1, 2026
GLPI
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass webhook signature verification.
The vulnerability exists due to incorrect comparison in webhook CRA signature verification when processing webhook requests. A remote attacker can perform a man-in-the-middle attack on a webhook request to bypass webhook signature verification.
Exploitation is possible only under very specific circumstances.