Skip to content

glpi

v11.0.8 Security

This release includes 16 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 16 known CVEs

Topics

asset-manager assets-management cmdb data-center dcim glpi
+8 more
helpdesk impact-analysis inventory itam itil itsm license-management ticketing

Affected surfaces

auth rbac rce_ssrf

Summary

AI summary

Updates CVE-2026-45801, CVE-2026-49469, and CVE-2026-53628 across a mixed release.

Full changelog

This is a security release, upgrading is recommended

You will find below the list of security issues fixed in this bugfixes version:

  • [SECURITY - Medium] Unauthorized debug mode activation (CVE-2026-45801)
  • [SECURITY - Medium] LDAP filter injection in user import feature (CVE-2026-49469)
  • [SECURITY - Medium] Unallowed authentication method update by administrator (CVE-2026-53628)
  • [SECURITY - Medium] Unexpected access to update operations through the API (CVE-2026-53627)
  • [SECURITY - Medium] Unallowed modification of knowbase items comments and translations (CVE-2026-55217)
  • [SECURITY - Medium] Unallowed notifications sending (CVE-2026-57152)
  • [SECURITY - High] SQL injection in dropdowns (CVE-2026-47678)
  • [SECURITY - High] Arbitrary file deletion (CVE-2026-47679)
  • [SECURITY - High] Account takeover via 2FA brute force (CVE-2026-49470)
  • [SECURITY - High] Privilege Escalation via authtype API manipulation (CVE-2026-53625)
  • [SECURITY - High] Reflected XSS in dashboards (CVE-2026-53610)
  • [SECURITY - High] Arbitrary document read (CVE-2026-53626)
  • [SECURITY - High] SQL injection in history tab (CVE-2026-53629)
  • [SECURITY - High] Stored XSS in suppliers (CVE-2026-55214)
  • [SECURITY - CRITICAL] RCE via Form import (CVE-2026-48482)
  • [SECURITY - CRITICAL] MFA bypass (CVE-2026-52848)

The full changelog is available for more details.

We would like to thank all people who contributed to this new version and all those who contributes regularly to the GLPI project!

Regards.

Security Fixes

  • CVE-2026-48482 — RCE via Form import (CRITICAL)
  • CVE-2026-52848 — MFA bypass (CRITICAL)
  • CVE-2026-47678 — SQL injection in dropdowns (High)
  • CVE-2026-47679 — Arbitrary file deletion (High)
  • CVE-2026-49470 — Account takeover via 2FA brute force (High)
  • CVE-2026-53625 — Privilege Escalation via authtype API manipulation (High)
  • CVE-2026-53610 — Reflected XSS in dashboards (High)
  • CVE-2026-53626 — Arbitrary document read (High)
  • CVE-2026-53629 — SQL injection in history tab (High)
  • CVE-2026-55214 — Stored XSS in suppliers (High)
  • CVE-2026-45801 — Unauthorized debug mode activation (Medium)
  • CVE-2026-49469 — LDAP filter injection in user import feature (Medium)
  • CVE-2026-53628 — Unallowed authentication method update by administrator (Medium)
  • CVE-2026-53627 — Unexpected access to update operations through the API (Medium)
  • CVE-2026-55217 — Unallowed modification of knowbase items comments and translations (Medium)
  • CVE-2026-57152 — Unallowed notifications sending (Medium)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track glpi

Get notified when new releases ship.

Sign up free

About glpi

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.

All releases →

Related context

Beta — feedback welcome: [email protected]