CVE-2026-23624: 
GLPI vulnerability analysis and mitigation

Overview

CVE-2026-23624 is a session fixation vulnerability (CWE-384) in GLPI, a free open-source asset and IT management software package. When remote authentication via SSO variables is used, a low-privileged user with physical access to a shared machine can steal a GLPI session previously opened by another user. The vulnerability affects GLPI versions from 0.71 up to (but not including) 10.0.23, and versions 11.0.0 through 11.0.4. It was published on February 4, 2026, and patched in versions 10.0.23 and 11.0.5 (GitHub Advisory). The NVD assigns a CVSS v3.1 score of 6.5 (Medium), while the GitHub advisory scores it 4.3 (Moderate) using a Physical attack vector (GitHub Advisory, Red Hat).

Technical details

The root cause is a session fixation flaw (CWE-384) in GLPI's handling of SSO/remote authentication variables. When a user authenticates via an external SSO provider, GLPI does not properly invalidate or regenerate session identifiers upon user context changes, allowing a different user on the same machine to assume the previously established session. An attacker with low privileges and physical access to the machine can manipulate SSO variables to hijack the active session of another authenticated user without requiring any interaction from the victim (GitHub Advisory). No public proof-of-concept exploit code has been identified at this time (Feedly).

Impact

Successful exploitation allows an attacker to impersonate another authenticated GLPI user, gaining unauthorized access to the IT asset management system with the privileges of the hijacked account. This can expose sensitive IT inventory data, configuration details, and other managed assets without the legitimate user's knowledge. The impact is limited to confidentiality (no integrity or availability impact), but in environments where GLPI manages critical infrastructure data, the exposure of asset and IT management information could facilitate further attacks (GitHub Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability requires low privileges and physical access to the target machine, which significantly limits the attacker pool. The EPSS score is approximately 0.043%, reflecting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Prerequisite: Obtain low-privileged access to a machine where GLPI is accessed via a browser and remote/SSO authentication is configured.
  2. Wait or observe: Identify that another user has an active GLPI session open on the same machine (e.g., a shared workstation or kiosk).
  3. Manipulate SSO variables: Leverage the SSO variable handling flaw — by modifying browser session data, cookies, or SSO-related environment variables accessible on the shared machine — to present the application with credentials or identifiers that cause GLPI to associate the attacker's request with the victim's existing session.
  4. Session hijack: GLPI, failing to regenerate or properly validate the session upon the user context change, grants the attacker access under the victim's authenticated session.
  5. Access sensitive data: Browse GLPI as the impersonated user, accessing IT asset inventory, configuration data, and other privileged information available to the victim's account (GitHub Advisory).

Indicators of compromise

  • Logs: GLPI access logs showing the same session ID used from different user accounts or with anomalous SSO variable values; authentication log entries reflecting unexpected user context switches without a new login event.
  • Network: Unusual session activity patterns where a session established by one user is subsequently used by a different user account, potentially visible in application-level audit logs.
  • Application: GLPI audit trail entries showing access to sensitive assets or configuration pages by a user account at times inconsistent with that user's normal activity, particularly on shared machines with SSO authentication enabled (GitHub Advisory).

Mitigation and workarounds

Upgrade GLPI to version 10.0.23 (for the 10.x branch) or 11.0.5 (for the 11.x branch), both released on January 28, 2026, as security releases (GLPI 10.0.23 Release, GLPI 11.0.5 Release). As an interim measure, restrict physical access to machines running GLPI sessions, avoid using GLPI on shared workstations with SSO authentication, and enforce session timeouts and logout policies. Regularly audit active sessions and monitor for anomalous session activity, especially in environments using remote/SSO authentication (GitHub Advisory).

Community reactions

The GLPI project team published the advisory and patched releases on January 28, 2026, with the CVE formally published on February 4, 2026. The vulnerability was reported by researcher 'silhusk' and credited in the GitHub Security Advisory (GitHub Advisory). Neteye published a security advisory referencing the GLPI issues, and Tenable added a Nessus detection plugin (ID 298327) for the vulnerability (Feedly). Community reaction has been moderate, consistent with the vulnerability's limited exploitability requirements.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Ubuntu

Unknown

xenial (esm-apps-legacy)

glpi

Unknown

Source: This report was generated using AI

Related GLPI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55214HIGH8.5
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53629HIGH7.1
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53627MEDIUM6
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53628MEDIUM5.9
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-55217MEDIUM5.3
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management