CVE-2026-53628Medium· 5.9▾ SunlitGLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or Update auth, sync and 2FA right can change the authentication method and disable two-factor…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or Update auth, sync and 2FA right can change the authentication method and disable two-factor authentication for user accounts outside the administrator's entity scope. The affected user-account administration flow did not consistently enforce the target user's entity-scoped update permission. This issue is fixed in versions 11.0.8 and 10.0.26.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55217Medium· 5.3GLPI is a free asset and IT management software package
CVE-2026-49469Medium· 4.6GLPI is a free asset and IT management software package
CVE-2026-45801Medium· 5.3GLPI is a free asset and IT management software package
CVE-2026-53629High· 7.1GLPI is a free asset and IT management software package
CVE-2026-47679High· 8.5GLPI is a free asset and IT management software package
CVE-2026-53625High· 7.5GLPI is a free asset and IT management software package