PT-2026-99072 · Glpi · Glpi

CVE-2026-53627

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GLPI versions 11.0.0 through 11.0.7
Description An issue exists where a low-privileged authenticated user can utilize the API (v2) to execute update operations that are typically restricted within the user interface. This occurs because the API update flow does not consistently enforce the required authorization checks.
Recommendations Update to version 11.0.8.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53627
GHSA-P68F-RV24-MC54

Affected Products

Glpi