PT-2026-99068 · Glpi · Glpi
CVE-2026-49470
·
Published
2026-09-25
·
Updated
2026-09-28
CVSS v4.0
7.7
High
| Vector | AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
GLPI versions 11.0.0 through 11.0.7
Description
The time-based one-time password (TOTP) verification endpoint does not limit failed submissions per user. An attacker with a user's primary authentication credentials can repeatedly submit TOTP values against the MFA verification flow, enabling a brute-force attack to compromise the second factor and achieve account takeover.
Recommendations
Update to version 11.0.8.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Glpi