Authorization bypass through user-controlled key in GLPI - CVE-2026-53626
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in document access permission logic when handling requests for documents linked to targeted items. A remote user can request access to a document to disclose sensitive information.
Exploitation is possible when the permission check does not properly verify that the document is actually linked to the targeted item.