Improper access control in GLPI - CVE-2026-57152
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in document permission logic when checking access to a document linked to a targeted item. A remote user can access a document without proper link confirmation to disclose sensitive information.
Exploitation is possible only under certain conditions.