Skip to content

glpi

v10.0.26 Security

This release includes 9 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 9 known CVEs

Topics

asset-manager assets-management cmdb data-center dcim glpi
+8 more
helpdesk impact-analysis inventory itam itil itsm license-management ticketing

Affected surfaces

auth rbac rce_ssrf breaking_upgrade

Summary

AI summary

Updates CVE-2026-45801, CVE-2026-49469, and CVE-2026-53628 across a mixed release.

Full changelog

This is a security release, upgrading is recommended

This release fixes a few security issues that have been recently discovered. Update is recommended!

You will find below the list of security issues fixed in this bugfixes version:

  • [SECURITY - Medium] Unauthorized debug mode activation (CVE-2026-45801)
  • [SECURITY - Medium] LDAP filter injection in user import feature (CVE-2026-49469)
  • [SECURITY - Medium] Unallowed authentication method update by administrator (CVE-2026-53628)
  • [SECURITY - Medium] Unallowed modification of knowbase items comments and translations (CVE-2026-55217)
  • [SECURITY - Medium] Unallowed notifications sending (CVE-2026-57152)
  • [SECURITY - High] SQL injection in dropdowns (CVE-2026-47678)
  • [SECURITY - High] Arbitrary file deletion (CVE-2026-47679)
  • [SECURITY - High] Privilege Escalation via authtype API manipulation (CVE-2026-53625)
  • [SECURITY - High] SQL injection in history tab (CVE-2026-53629)

Many bug fixes have also been made, read the full changelog is available for more details.

We would like to thank all people who contributed to this new version and all those who contributes regularly to the GLPI project!

Regards.

Security Fixes

  • CVE-2026-45801 — Medium: Unauthorized debug mode activation
  • CVE-2026-49469 — Medium: LDAP filter injection in user import feature
  • CVE-2026-53628 — Medium: Unallowed authentication method update by administrator
  • CVE-2026-55217 — Medium: Unallowed modification of knowbase items comments and translations
  • CVE-2026-57152 — Medium: Unallowed notifications sending
  • CVE-2026-47678 — High: SQL injection in dropdowns
  • CVE-2026-47679 — High: Arbitrary file deletion
  • CVE-2026-53625 — High: Privilege Escalation via authtype API manipulation
  • CVE-2026-53629 — High: SQL injection in history tab

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track glpi

Get notified when new releases ship.

Sign up free

About glpi

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.

All releases →

Related context

Beta — feedback welcome: [email protected]