PT-2026-99073 · Glpi · Glpi
CVE-2026-53628
·
Published
2026-09-25
·
Updated
2026-09-30
CVSS v4.0
5.9
Medium
| Vector | AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
GLPI versions 0.84 through 10.0.25
GLPI versions 11.0.0 through 11.0.7
Description
An administrator with Update auth and sync or Update auth, sync and 2FA permissions can modify the authentication method and disable two-factor authentication for user accounts outside their assigned entity scope. This occurs because the user-account administration flow fails to consistently enforce entity-scoped update permissions for the target user.
Recommendations
Update to version 10.0.26.
Update to version 11.0.8.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Glpi