---
id: CVE-2026-53627
title: GLPI is a free asset and IT management software package
summary: >-
  GLPI is a free asset and IT management software package. From 11.0.0 until
  11.0.8, a low-privileged authenticated user can use the new API (v2) to
  perform update operations that the same user is normally forbidden to perform
  through the …
severity: medium
cvss: 6
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'
cwe:
  - CWE-862
vendor: glpi-project
product: glpi
affected:
  - 'glpi >= 11.0.0, < 11.0.8'
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T19:17:28.007'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53627'
references:
  - url: >-
      https://github.com/glpi-project/glpi/commit/0fdd973c4bb3f203c6905a62a93512e5ca8604c0
    label: security-advisories@github.com
  - url: 'https://github.com/glpi-project/glpi/releases/tag/11.0.8'
    label: security-advisories@github.com
  - url: >-
      https://github.com/glpi-project/glpi/security/advisories/GHSA-p68f-rv24-mc54
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-25T19:03:25.690853Z'
cvssSource: cna
ingestedAt: '2026-09-25T19:15:38.965Z'
---

## Overview

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to perform update operations that the same user is normally forbidden to perform through the user interface. The API update flow does not consistently enforce the applicable authorization checks. This issue is fixed in version 11.0.8.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
