Improper access control in GLPI - CVE-2026-53625
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in the authtype API when handling authentication method changes for user accounts. A remote privileged user can modify the authentication method of another user account to escalate privileges.
Under specific conditions, this may be used to target a super-admin account and steal access to that account.