Improper access control in GLPI - #VU153889
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in template-generated followups, tasks, and solutions when handling access to these items. A remote user can access followups, tasks, and solutions generated from templates to disclose sensitive information.
Exposure of information from tickets, problems, or changes depends on the templates configuration.