Improper access control in GLPI - #VU133156
Published: June 1, 2026
GLPI
Detailed vulnerability description
The vulnerability allows a remote user to probe IMAP servers through the application.
The vulnerability exists due to improper access control in the IMAP connection testing functionality when handling configuration-related requests. A remote user can send a crafted request to probe IMAP servers through the application.
The issue requires config READ permission.