---
id: CVE-2026-49469
title: GLPI is a free asset and IT management software package
summary: >-
  GLPI is a free asset and IT management software package. From 0.70 until
  10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted
  criteria through the user import feature to bypass the configured default LDAP
  filter…
severity: medium
cvss: 4.6
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N'
cwe:
  - CWE-90
vendor: glpi-project
product: glpi
affected:
  - 'glpi >= 0.70, < 10.0.26'
  - 'glpi >= 11.0.0, < 11.0.8'
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T19:16:58.163'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-49469'
references:
  - url: >-
      https://github.com/glpi-project/glpi/commit/4fb3056bcd292b515acce96887f1376ce6d5aba8
    label: security-advisories@github.com
  - url: >-
      https://github.com/glpi-project/glpi/commit/d413b48ea97b2f73ba30c90ae0d029aac860f71a
    label: security-advisories@github.com
  - url: 'https://github.com/glpi-project/glpi/releases/tag/10.0.26'
    label: security-advisories@github.com
  - url: 'https://github.com/glpi-project/glpi/releases/tag/11.0.8'
    label: security-advisories@github.com
  - url: >-
      https://github.com/glpi-project/glpi/security/advisories/GHSA-3cgm-rj32-hfwf
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-25T19:15:38.972Z'
---

## Overview

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP filter. This allows access to LDAP objects that the default filter was intended to exclude. This issue is fixed in versions 11.0.8 and 10.0.26.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
