Missing Authorization in GLPI - #VU133159
Published: June 1, 2026
GLPI
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in asset object access control when handling requests for a specific asset object. A remote user can request a specific asset object to disclose sensitive information.
Exploitation requires config READ permission.