CVE-2026-49469Medium· 4.6▾ SunlitGLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP filter…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP filter. This allows access to LDAP objects that the default filter was intended to exclude. This issue is fixed in versions 11.0.8 and 10.0.26.
glpi >= 0.70, < 10.0.26glpi >= 11.0.0, < 11.0.8Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-45801Medium· 5.3GLPI: Unauthorized Debug Mode Activation via Profile Update (Privilege Escalation)
CVE-2026-53628Medium· 5.9GLPI: Unallowed authentication method update by administrator
CVE-2026-53629High· 7.1GLPI: SQL injection in history tab
CVE-2026-55217Medium· 5.3GLPI: Unallowed modfication of knowbase items comments and translations
CVE-2026-47679High· 8.5GLPI: arbitrary file deletion
CVE-2026-53625High· 7.5GLPI: Privilege Escalation via authtype API manipulation