CVE-2026-44281
Deferred
Deferred - Pending Action
Authenticated Asset Object Read in GLPI
Publication date: 2026-06-03
Last updated on: 2026-06-03
Assigner: GitHub, Inc.
Description
Description
GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user with config READ permission can read a specific asset object. Upgrade to 11.0.7 or 10.0.25 to receive a patch.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| glpi_project | glpi | to 10.0.25|end_excluding=11.0.7 (exc) |
| glpi_project | glpi | From 11.0.0 (inc) |
| glpi_project | glpi | 11.0.7 |
| glpi_project | glpi | 10.0.25 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |