Authorization bypass through user-controlled key in GLPI - CVE-2026-53626

 

Authorization bypass through user-controlled key in GLPI - CVE-2026-53626

Published: July 27, 2026


Vulnerability identifier: #VU139545
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53626
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in document access permission logic when handling requests for documents linked to targeted items. A remote user can request access to a document to disclose sensitive information.

Exploitation is possible when the permission check does not properly verify that the document is actually linked to the targeted item.


Affected software

GLPI

How to mitigate CVE-2026-53626

Install security update from vendor's website.

GLPI - update to 11.0.8

External References

Related Security Bulletins