Improper Authorization in GLPI - CVE-2026-53628
Published: July 21, 2026
GLPI
Detailed vulnerability description
The vulnerability allows a remote user to modify users' authentication methods and disable two-factor authentication outside the intended entity scope.
The vulnerability exists due to improper authorization in the authentication method update functionality when handling administrative updates to user authentication settings. A remote privileged user can change authentication methods for users outside their entity scope to modify users' authentication methods and disable two-factor authentication outside the intended entity scope.
Exploitation requires the "Update auth and sync" or "Update auth, sync and 2FA" right.