
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64516 is an improper access control vulnerability in GLPI (free asset and IT management software) that allows unauthorized users to access documents attached to any GLPI item, including tickets and assets. When the public FAQ feature is enabled, completely anonymous users can exploit this flaw without any authentication. Affected versions include GLPI 10.0.0 through 10.0.20 and 11.0.0 through 11.0.2. The vulnerability was disclosed on January 15, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Feedly). It was initially reported by Aras Duzen, with a second attack vector identified by TRUESEC (GitHub Advisory).
The root cause lies in flawed document relation filtering within src/Document.php, classified as CWE-284 (Improper Access Control), CWE-639 (Authorization Bypass Through User-Controlled Key), and CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) (GitHub Advisory). Two specific bugs were identified: the canViewFileFromKnowbaseItem() method used a LEFT JOIN instead of an INNER JOIN when querying knowledge base item relationships, allowing documents unrelated to FAQ items to pass the visibility check; and the canViewFileFromItem() method's SQL query was missing a documents_id filter, meaning any document could be accessed by supplying a valid itemtype/items_id pair in the URL regardless of whether the document was actually attached to that item (GitHub Commit 51412a8, GitHub Commit ee7ee28). A public proof-of-concept repository (lem0naids/CVE-2025-64516-POC) appeared on GitHub shortly after disclosure.
Successful exploitation results in high confidentiality impact, allowing attackers to retrieve sensitive documents — such as attachments to IT tickets, asset records, or other GLPI items — without authorization (GitHub Advisory). There is no integrity or availability impact. When the public FAQ feature is active, the attack surface expands to the entire internet, as anonymous users can access all attached documents without any credentials or user interaction (Feedly). Exposed documents may contain sensitive organizational data such as network diagrams, credentials, contracts, or incident details stored within GLPI.
A public proof-of-concept repository (https://github.com/lem0naids/CVE-2025-64516-POC) was published shortly after disclosure, lowering the barrier to exploitation. The EPSS score is approximately 0.033% (0.000330), indicating currently low predicted exploitation probability (Feedly). There is no confirmed evidence of active in-the-wild exploitation or threat actor attribution at this time. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack requires no privileges and no user interaction, making it trivially exploitable against internet-facing GLPI instances with public FAQ enabled.
/front/helpdesk.faq.php) without authentication. If accessible, anonymous document access is possible via the knowledge base vector./front/document.send.php?docid=<ID>) with sequential or guessed document IDs.itemtype and items_id parameter in the document request URL. Due to the missing documents_id filter in canViewFileFromItem(), the server confirms the item exists and grants access to the document regardless of whether it is actually attached to that item./front/document.send.php with varying docid parameters; requests originating from unexpected IPs with no prior authenticated session.docid values in document download requests from unauthenticated sessions; requests to document endpoints accompanied by itemtype and items_id parameters from anonymous users.The primary remediation is to upgrade GLPI to version 10.0.21 (for the 10.x branch) or 11.0.3 (for the 11.x branch), both of which contain the patched Document.php with corrected SQL filtering (GLPI Release 10.0.21, GLPI Release 11.0.3). For organizations unable to patch immediately, disabling the public FAQ feature (use_public_faq = 0) eliminates the anonymous access vector, though authenticated low-privilege users may still be affected (Feedly). Additionally, implementing network-level access controls to restrict GLPI access to authorized users and reviewing access logs for unauthorized document download attempts are recommended interim measures.
The GLPI project issued a security advisory classifying this as a High severity issue and credited Aras Duzen for the initial report and TRUESEC for identifying a second attack vector (GitHub Advisory). Both the 10.0.21 and 11.0.3 releases were explicitly designated as security releases with upgrade strongly recommended (GLPI Release 10.0.21, GLPI Release 11.0.3). Community discussion appeared on the GLPI project forum, and the vulnerability was noted on infosec social media (Mastodon/TheHackerWire). Tenable published a Nessus detection plugin (ID 297688) for this vulnerability.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."