Improper access control in GLPI - CVE-2026-53627
Published: July 21, 2026
GLPI
Detailed vulnerability description
The vulnerability allows a remote user to perform unauthorized update operations.
The vulnerability exists due to improper access control in the API v2 when handling update requests. A remote user can send crafted API requests to perform unauthorized update operations.
The issue affects operations that are forbidden to low-privilege users through the user interface.