CVE-2026-44281
Received Received - Intake
Authenticated Asset Object Read in GLPI

Publication date: 2026-06-03

Last updated on: 2026-06-03

Assigner: GitHub, Inc.

Description
GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user with config READ permission can read a specific asset object. Upgrade to 11.0.7 or 10.0.25 to receive a patch.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-03
Last Modified
2026-06-03
Generated
2026-06-03
AI Q&A
2026-06-03
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 4 associated CPEs
Vendor Product Version / Range
glpi_project glpi to 10.0.25|end_excluding=11.0.7 (exc)
glpi_project glpi From 11.0.0 (inc)
glpi_project glpi 11.0.7
glpi_project glpi 10.0.25
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in GLPI, an asset and IT management software, where an authenticated user with config READ permission can read a specific asset object without proper authorization.

It is classified as a missing authorization issue (CWE-862), meaning that the software does not correctly restrict access to certain asset data.

The issue affects GLPI versions starting from 0.78 up to versions before 10.0.25 and 11.0.7, and it has been patched in version 11.0.7.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The vulnerability allows an authenticated user with config READ permission to read a specific asset object without proper authorization, which could lead to unauthorized access to sensitive asset data.

Such unauthorized access to asset information may impact compliance with data protection standards and regulations like GDPR and HIPAA, which require strict controls on access to sensitive information.

However, the severity is rated as low and the issue has been patched in version 11.0.7, so upgrading mitigates the compliance risk.


How can this vulnerability impact me? :

This vulnerability allows an authenticated user with config READ permission to access asset data that they should not be authorized to see.

Such unauthorized access could lead to exposure of sensitive asset information, potentially compromising the confidentiality of IT asset management data.

The severity is rated as low, but it still represents a risk of unauthorized data disclosure within the system.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, upgrade GLPI to version 11.0.7 or 10.0.25 or later, where the issue has been patched.

Ensure that only trusted authenticated users have config READ permissions to limit exposure.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart