CVE-2025-64516: 
GLPI vulnerability analysis and mitigation

Overview

CVE-2025-64516 is an improper access control vulnerability in GLPI (free asset and IT management software) that allows unauthorized users to access documents attached to any GLPI item, including tickets and assets. When the public FAQ feature is enabled, completely anonymous users can exploit this flaw without any authentication. Affected versions include GLPI 10.0.0 through 10.0.20 and 11.0.0 through 11.0.2. The vulnerability was disclosed on January 15, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Feedly). It was initially reported by Aras Duzen, with a second attack vector identified by TRUESEC (GitHub Advisory).

Technical details

The root cause lies in flawed document relation filtering within src/Document.php, classified as CWE-284 (Improper Access Control), CWE-639 (Authorization Bypass Through User-Controlled Key), and CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) (GitHub Advisory). Two specific bugs were identified: the canViewFileFromKnowbaseItem() method used a LEFT JOIN instead of an INNER JOIN when querying knowledge base item relationships, allowing documents unrelated to FAQ items to pass the visibility check; and the canViewFileFromItem() method's SQL query was missing a documents_id filter, meaning any document could be accessed by supplying a valid itemtype/items_id pair in the URL regardless of whether the document was actually attached to that item (GitHub Commit 51412a8, GitHub Commit ee7ee28). A public proof-of-concept repository (lem0naids/CVE-2025-64516-POC) appeared on GitHub shortly after disclosure.

Impact

Successful exploitation results in high confidentiality impact, allowing attackers to retrieve sensitive documents — such as attachments to IT tickets, asset records, or other GLPI items — without authorization (GitHub Advisory). There is no integrity or availability impact. When the public FAQ feature is active, the attack surface expands to the entire internet, as anonymous users can access all attached documents without any credentials or user interaction (Feedly). Exposed documents may contain sensitive organizational data such as network diagrams, credentials, contracts, or incident details stored within GLPI.

Exploitability

A public proof-of-concept repository (https://github.com/lem0naids/CVE-2025-64516-POC) was published shortly after disclosure, lowering the barrier to exploitation. The EPSS score is approximately 0.033% (0.000330), indicating currently low predicted exploitation probability (Feedly). There is no confirmed evidence of active in-the-wild exploitation or threat actor attribution at this time. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack requires no privileges and no user interaction, making it trivially exploitable against internet-facing GLPI instances with public FAQ enabled.

Exploitation steps

  1. Reconnaissance: Identify internet-facing GLPI instances running versions 10.0.0–10.0.20 or 11.0.0–11.0.2 using search engines (Shodan, Censys) or by browsing to the GLPI login page, which typically displays the version number.
  2. Check public FAQ status: Attempt to access the public FAQ endpoint (e.g., /front/helpdesk.faq.php) without authentication. If accessible, anonymous document access is possible via the knowledge base vector.
  3. Enumerate document IDs: Iterate over document IDs by crafting requests to the GLPI document download endpoint (e.g., /front/document.send.php?docid=<ID>) with sequential or guessed document IDs.
  4. Bypass item-based access check: Supply a valid itemtype and items_id parameter in the document request URL. Due to the missing documents_id filter in canViewFileFromItem(), the server confirms the item exists and grants access to the document regardless of whether it is actually attached to that item.
  5. Retrieve documents: Download the returned document files, which may include sensitive attachments from tickets, assets, or other GLPI records (GitHub Commit 51412a8, GitHub Advisory).

Indicators of compromise

  • Network: Unusual or high-volume unauthenticated HTTP GET requests to /front/document.send.php with varying docid parameters; requests originating from unexpected IPs with no prior authenticated session.
  • Logs: Web server access logs showing sequential or enumerated docid values in document download requests from unauthenticated sessions; requests to document endpoints accompanied by itemtype and items_id parameters from anonymous users.
  • Application Logs: GLPI application logs showing document access events for items the requesting user has no legitimate relationship to; repeated 200 OK responses to document download requests from unauthenticated sessions when public FAQ is enabled.

Mitigation and workarounds

The primary remediation is to upgrade GLPI to version 10.0.21 (for the 10.x branch) or 11.0.3 (for the 11.x branch), both of which contain the patched Document.php with corrected SQL filtering (GLPI Release 10.0.21, GLPI Release 11.0.3). For organizations unable to patch immediately, disabling the public FAQ feature (use_public_faq = 0) eliminates the anonymous access vector, though authenticated low-privilege users may still be affected (Feedly). Additionally, implementing network-level access controls to restrict GLPI access to authorized users and reviewing access logs for unauthorized document download attempts are recommended interim measures.

Community reactions

The GLPI project issued a security advisory classifying this as a High severity issue and credited Aras Duzen for the initial report and TRUESEC for identifying a second attack vector (GitHub Advisory). Both the 10.0.21 and 11.0.3 releases were explicitly designated as security releases with upgrade strongly recommended (GLPI Release 10.0.21, GLPI Release 11.0.3). Community discussion appeared on the GLPI project forum, and the vulnerability was noted on infosec social media (Mastodon/TheHackerWire). Tenable published a Nessus detection plugin (ID 297688) for this vulnerability.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Ubuntu

Unknown

xenial (esm-apps-legacy)

glpi

Unknown

Source: This report was generated using AI

Related GLPI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55214HIGH8.5
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53629HIGH7.1
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53627MEDIUM6
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53628MEDIUM5.9
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-55217MEDIUM5.3
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management