CVE-2026-22044: 
GLPI vulnerability analysis and mitigation

Overview

CVE-2026-22044 is an authenticated SQL injection vulnerability in GLPI, a free open-source asset and IT management software package. It affects all versions from 0.85 up to (but not including) 10.0.23, and was disclosed on February 4, 2026. The vulnerability was reported by researcher Guilhem7 and patched in GLPI version 10.0.23, released January 28, 2026. The GitHub Security Advisory assigns a CVSS v3.1 score of 6.5 (Moderate), while NVD rates it 8.8 (High) (GitHub Advisory, GLPI Release).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning GLPI fails to adequately sanitize or parameterize user-supplied input before incorporating it into SQL queries. An authenticated user with low privileges can craft malicious input to manipulate the underlying SQL command executed by the application. The attack is network-based, requires no user interaction, and has low attack complexity, making it straightforward to exploit once an attacker has any valid account. No specific vulnerable endpoint or payload has been publicly disclosed (GitHub Advisory).

Impact

Successful exploitation allows an authenticated low-privilege attacker to read sensitive data from the GLPI database, including asset inventory records, user credentials, configuration details, and other confidential information managed by the platform. The GitHub advisory rates confidentiality impact as High with no integrity or availability impact, indicating this is primarily a data exposure vulnerability. In environments where GLPI manages IT assets and user accounts across an organization, database access could facilitate further attacks such as credential harvesting or lateral movement (GitHub Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.035%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated account, which limits the attacker pool but does not eliminate risk in multi-tenant or externally accessible GLPI deployments.

Mitigation and workarounds

The primary remediation is to upgrade GLPI to version 10.0.23 or later, which contains the fix for this SQL injection vulnerability (GLPI Release). Until patching is possible, organizations should implement strict access controls to limit the number of authenticated users with access to GLPI instances, and monitor database query logs for anomalous or unexpected SQL patterns. Reviewing user access logs for unusual activity from low-privilege accounts is also recommended as a compensating control (Feedly).

Community reactions

The GLPI project team classified the issue as Moderate severity and included the fix in the 10.0.23 security release alongside a session-stealing vulnerability fix (CVE-2026-23624), recommending all users upgrade (GLPI Release). Wuerth IT's NetEye blog published a security advisory noting the GLPI update, and Tenable released a Nessus plugin (ID 298331) to detect vulnerable installations. No significant broader community or social media discussion has been observed beyond standard vulnerability tracking platforms.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Ubuntu

Unknown

xenial (esm-apps-legacy)

glpi

Unknown

Source: This report was generated using AI

Related GLPI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55214HIGH8.5
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53629HIGH7.1
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53627MEDIUM6
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53628MEDIUM5.9
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-55217MEDIUM5.3
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management