
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22044 is an authenticated SQL injection vulnerability in GLPI, a free open-source asset and IT management software package. It affects all versions from 0.85 up to (but not including) 10.0.23, and was disclosed on February 4, 2026. The vulnerability was reported by researcher Guilhem7 and patched in GLPI version 10.0.23, released January 28, 2026. The GitHub Security Advisory assigns a CVSS v3.1 score of 6.5 (Moderate), while NVD rates it 8.8 (High) (GitHub Advisory, GLPI Release).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning GLPI fails to adequately sanitize or parameterize user-supplied input before incorporating it into SQL queries. An authenticated user with low privileges can craft malicious input to manipulate the underlying SQL command executed by the application. The attack is network-based, requires no user interaction, and has low attack complexity, making it straightforward to exploit once an attacker has any valid account. No specific vulnerable endpoint or payload has been publicly disclosed (GitHub Advisory).
Successful exploitation allows an authenticated low-privilege attacker to read sensitive data from the GLPI database, including asset inventory records, user credentials, configuration details, and other confidential information managed by the platform. The GitHub advisory rates confidentiality impact as High with no integrity or availability impact, indicating this is primarily a data exposure vulnerability. In environments where GLPI manages IT assets and user accounts across an organization, database access could facilitate further attacks such as credential harvesting or lateral movement (GitHub Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.035%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated account, which limits the attacker pool but does not eliminate risk in multi-tenant or externally accessible GLPI deployments.
The primary remediation is to upgrade GLPI to version 10.0.23 or later, which contains the fix for this SQL injection vulnerability (GLPI Release). Until patching is possible, organizations should implement strict access controls to limit the number of authenticated users with access to GLPI instances, and monitor database query logs for anomalous or unexpected SQL patterns. Reviewing user access logs for unusual activity from low-privilege accounts is also recommended as a compensating control (Feedly).
The GLPI project team classified the issue as Moderate severity and included the fix in the 10.0.23 security release alongside a session-stealing vulnerability fix (CVE-2026-23624), recommending all users upgrade (GLPI Release). Wuerth IT's NetEye blog published a security advisory noting the GLPI update, and Tenable released a Nessus plugin (ID 298331) to detect vulnerable installations. No significant broader community or social media discussion has been observed beyond standard vulnerability tracking platforms.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."