---
id: CVE-2026-53629
title: GLPI is a free asset and IT management software package
summary: >-
  GLPI is a free asset and IT management software package. From 9.4.0 until
  10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL
  for the history tab that injects attacker-controlled values into a database
  query. This…
severity: high
cvss: 7.1
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N'
cwe:
  - CWE-89
vendor: glpi-project
product: glpi
affected:
  - 'glpi >= 9.4.0, < 10.0.26'
  - 'glpi >= 11.0.0, < 11.0.8'
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T20:17:07.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53629'
references:
  - url: >-
      https://github.com/glpi-project/glpi/commit/1296798fb03295d07c1d97fa8483d1dbab59fef5
    label: security-advisories@github.com
  - url: >-
      https://github.com/glpi-project/glpi/commit/80b86c0dcad2f6ece9b5da445d1c264a1dda3ce5
    label: security-advisories@github.com
  - url: 'https://github.com/glpi-project/glpi/releases/tag/10.0.26'
    label: security-advisories@github.com
  - url: 'https://github.com/glpi-project/glpi/releases/tag/11.0.8'
    label: security-advisories@github.com
  - url: >-
      https://github.com/glpi-project/glpi/security/advisories/GHSA-cpcj-x335-5cmh
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
  - exploit-available
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-25T19:45:11.103391Z'
cvssSource: cna
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/5kr1pt/glpi-logbleed'
  nuclei:
    - CVE-2026-53629
  checkedAt: '2026-09-25T20:18:24.162Z'
exploitAvailable: true
ingestedAt: '2026-09-25T19:15:38.968Z'
---

## Overview

GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL for the history tab that injects attacker-controlled values into a database query. This permits SQL injection through the history tab endpoint. This issue is fixed in versions 11.0.8 and 10.0.26.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
