CVE-2026-53627
Deferred Deferred - Pending Action

Authenticated API Update Privilege Escalation in GLPI

Vulnerability report for CVE-2026-53627, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: GitHub, Inc.

Description

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to perform update operations that the same user is normally forbidden to perform through the user interface. The API update flow does not consistently enforce the applicable authorization checks. This issue is fixed in version 11.0.8.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
glpi glpi to 11.0.8 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in GLPI (versions 11.0.0 to 11.0.8) allows a low-privileged authenticated user to perform unauthorized update operations via the API (v2) that would normally be restricted through the user interface. The issue stems from inconsistent authorization checks in the API update flow.

Detection Guidance

This vulnerability can be detected by checking the GLPI software version. If your system is running a version between 11.0.0 and 11.0.7, it is vulnerable. Use the command 'glpi --version' or check the version in the web interface under 'Setup > About GLPI'.

Impact Analysis

An attacker with low privileges could exploit this to modify data or settings they are not authorized to change, potentially leading to unauthorized access, data corruption, or system misconfigurations. This could affect the integrity and confidentiality of the IT asset management system.

Compliance Impact

This vulnerability could lead to unauthorized data modifications or access, which may violate compliance requirements for data integrity and access controls in standards like GDPR and HIPAA. Organizations using affected GLPI versions may face compliance risks due to insufficient authorization enforcement.

Mitigation Strategies

Upgrade GLPI to version 11.0.8 or later to fix the authorization bypass in the API update flow.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53627. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart