CVE-2026-53626
Deferred Deferred - Pending Action

Permission Logic Flaw in GLPI Allows Document Access

Vulnerability report for CVE-2026-53626, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: GitHub, Inc.

Description

GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. A user can use an unrelated item that the user is permitted to view to read a document linked to an inaccessible item. This issue is fixed in version 11.0.8.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
glpi glpi From 11.0.5 (inc) to 11.0.8 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in GLPI allows users to access documents linked to items they are not permitted to view. The permission logic fails to confirm document-item linkage, letting unauthorized users read sensitive files by exploiting unrelated accessible items.

Impact Analysis

An attacker could exploit this to read confidential documents they should not access, potentially exposing sensitive data like IT asset details, user information, or internal records. This could lead to data breaches or compliance violations.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data without authorization and HIPAA by allowing unauthorized access to protected health information. Organizations using affected GLPI versions may face legal penalties and reputational damage.

Mitigation Strategies

Upgrade GLPI to version 11.0.8 or later to address the permission logic flaw that allows unauthorized document access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53626. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart