LDAP injection in GLPI - CVE-2026-49469
Published: July 21, 2026
GLPI
Detailed vulnerability description
The vulnerability allows a remote user to access unexpected objects on the LDAP server.
The vulnerability exists due to improper neutralization of special elements used in an LDAP query in the user import feature when processing LDAP filter input. A remote privileged user can supply a crafted LDAP filter to access unexpected objects on the LDAP server.
The issue allows bypass of the default LDAP filter.