CVE-2020-11033
GLPI vulnerability analysis and mitigation

Overview

CVE-2020-11033 is a security vulnerability discovered in GLPI (IT asset management software) affecting versions since 9.1. The vulnerability was disclosed on May 5, 2020, and allows any API user with READ permissions on the User itemtype to access sensitive information when querying apirest.php/User endpoint (GitHub Advisory).

Technical details

The vulnerability exists in the API endpoint response which exposes all api_tokens and personal_tokens when querying the User endpoint. This exposure occurs even with basic READ permissions on the User itemtype. The issue requires the API to be enabled and a technician account to exploit (GitHub Advisory).

Impact

The exposure of api_tokens can lead to privilege escalation and unauthorized access to read, update, or delete data that would normally be inaccessible to the current user. Additionally, exposed personal_tokens can be used to view other users' planning information (GitHub Advisory).

Exploitability

The vulnerability requires an attacker to have API access and a technician account with READ permissions on the User itemtype. The exploitation is straightforward once these conditions are met, as it only requires querying the apirest.php/User endpoint (GitHub Advisory).

Mitigation and workarounds

The vulnerability was patched in GLPI version 9.4.6. For systems that cannot immediately update, several workarounds are available: disable the API functionality, disable user READ permissions for affected profiles, or add temporary app tokens to prevent users from testing the API without knowing the application token. The fix was implemented in commit 9f1117d (GitHub Advisory, Fedora Update).

Additional resources


SourceThis report was generated using AI

Related GLPI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-42321HIGH8.4
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026
CVE-2026-44281HIGH7
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026
CVE-2026-42318HIGH7
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026
CVE-2026-13490MEDIUM6.3
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 28, 2026
CVE-2026-42320MEDIUM5.9
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management