---
id: CVE-2026-42318
title: GLPI is a free asset and IT management software package
summary: >-
  GLPI is a free asset and IT management software package. Starting in version
  9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with
  access to planning can delete any object in GLPI. Upgrade to 11.0.7 or 10.0.25
  to recei…
severity: none
cwe:
  - CWE-862
published: '2026-06-03'
updated: '2026-08-21'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42318'
references:
  - url: >-
      https://github.com/glpi-project/glpi/security/advisories/GHSA-w7mr-3vwm-2j22
    label: security-advisories@github.com
  - url: 'https://vokecyber.com/research/cve-2026-42318-glpi-arbitrary-deletion'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00403
epssPercentile: 0.31763
ingestedAt: '2026-08-22T13:32:34.515Z'
---

## Overview

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with access to planning can delete any object in GLPI. Upgrade to 11.0.7 or 10.0.25 to receive a patch. As a workaround, disable delete rights for User's planning.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
