CVE-2026-53626High· 7.1▾ TwilightGLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. A user can …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. A user can use an unrelated item that the user is permitted to view to read a document linked to an inaccessible item. This issue is fixed in version 11.0.8.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53627Medium· 6.0GLPI is a free asset and IT management software package
CVE-2026-53625High· 7.5GLPI is a free asset and IT management software package
CVE-2026-49469Medium· 4.6GLPI is a free asset and IT management software package
CVE-2026-45801Medium· 5.3GLPI is a free asset and IT management software package
CVE-2026-53628Medium· 5.9GLPI is a free asset and IT management software package
CVE-2026-49470High· 7.7GLPI is a free asset and IT management software package