
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23624 is a session fixation vulnerability (CWE-384) in GLPI, a free open-source asset and IT management software package. When remote authentication via SSO variables is used, a low-privileged user with physical access to a shared machine can steal a GLPI session previously opened by another user. The vulnerability affects GLPI versions from 0.71 up to (but not including) 10.0.23, and versions 11.0.0 through 11.0.4. It was published on February 4, 2026, and patched in versions 10.0.23 and 11.0.5 (GitHub Advisory). The NVD assigns a CVSS v3.1 score of 6.5 (Medium), while the GitHub advisory scores it 4.3 (Moderate) using a Physical attack vector (GitHub Advisory, Red Hat).
The root cause is a session fixation flaw (CWE-384) in GLPI's handling of SSO/remote authentication variables. When a user authenticates via an external SSO provider, GLPI does not properly invalidate or regenerate session identifiers upon user context changes, allowing a different user on the same machine to assume the previously established session. An attacker with low privileges and physical access to the machine can manipulate SSO variables to hijack the active session of another authenticated user without requiring any interaction from the victim (GitHub Advisory). No public proof-of-concept exploit code has been identified at this time (Feedly).
Successful exploitation allows an attacker to impersonate another authenticated GLPI user, gaining unauthorized access to the IT asset management system with the privileges of the hijacked account. This can expose sensitive IT inventory data, configuration details, and other managed assets without the legitimate user's knowledge. The impact is limited to confidentiality (no integrity or availability impact), but in environments where GLPI manages critical infrastructure data, the exposure of asset and IT management information could facilitate further attacks (GitHub Advisory, Feedly).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability requires low privileges and physical access to the target machine, which significantly limits the attacker pool. The EPSS score is approximately 0.043%, reflecting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Upgrade GLPI to version 10.0.23 (for the 10.x branch) or 11.0.5 (for the 11.x branch), both released on January 28, 2026, as security releases (GLPI 10.0.23 Release, GLPI 11.0.5 Release). As an interim measure, restrict physical access to machines running GLPI sessions, avoid using GLPI on shared workstations with SSO authentication, and enforce session timeouts and logout policies. Regularly audit active sessions and monitor for anomalous session activity, especially in environments using remote/SSO authentication (GitHub Advisory).
The GLPI project team published the advisory and patched releases on January 28, 2026, with the CVE formally published on February 4, 2026. The vulnerability was reported by researcher 'silhusk' and credited in the GitHub Security Advisory (GitHub Advisory). Neteye published a security advisory referencing the GLPI issues, and Tenable added a Nessus detection plugin (ID 298327) for the vulnerability (Feedly). Community reaction has been moderate, consistent with the vulnerability's limited exploitability requirements.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."