CVE-2026-53629

Publication date 29 September 2026

Last updated 30 September 2026


Ubuntu priority

Description

GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL for the history tab that injects attacker-controlled values into a database query. This permits SQL injection through the history tab endpoint. This issue is fixed in versions 11.0.8 and 10.0.26.

Status

Package Ubuntu Release Status
glpi 26.04 LTS resolute Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
16.04 LTS xenial
Needs evaluation

Severity score breakdown

CVSS version: CVSS v4.0

Base score 7.1 · High

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N


Access our resources on patching vulnerabilities