LDAP injection in GLPI - CVE-2026-49469

 

LDAP injection in GLPI - CVE-2026-49469

Published: July 21, 2026


Vulnerability identifier: #VU138963
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-49469
CWE-ID: CWE-90
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: glpi-project
Affected software:
GLPI

Detailed vulnerability description

The vulnerability allows a remote user to access unexpected objects on the LDAP server.

The vulnerability exists due to improper neutralization of special elements used in an LDAP query in the user import feature when processing LDAP filter input. A remote privileged user can supply a crafted LDAP filter to access unexpected objects on the LDAP server.

The issue allows bypass of the default LDAP filter.


How to mitigate CVE-2026-49469

Install security update from vendor's website.

Sources