PT-2026-99073 · Glpi · Glpi

CVE-2026-53628

·

Published

2026-09-25

·

Updated

2026-09-30

CVSS v4.0

5.9

Medium

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GLPI versions 0.84 through 10.0.25 GLPI versions 11.0.0 through 11.0.7
Description An administrator with Update auth and sync or Update auth, sync and 2FA permissions can modify the authentication method and disable two-factor authentication for user accounts outside their assigned entity scope. This occurs because the user-account administration flow fails to consistently enforce entity-scoped update permissions for the target user.
Recommendations Update to version 10.0.26. Update to version 11.0.8.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53628
GHSA-2HF7-PW75-7WCP

Affected Products

Glpi