CVE-2026-25936: 
GLPI vulnerability analysis and mitigation

Overview

CVE-2026-25936 is an authenticated SQL injection vulnerability in GLPI, a free Asset and IT management software package developed by Teclib. It affects GLPI versions 11.0.0 through 11.0.5, and was patched in version 11.0.6. The vulnerability was published on March 17, 2026, and was reported by the security researcher "login-securite." The GitHub Security Advisory assigns a CVSS v3.1 score of 6.5 (Moderate), while NVD rates it 8.8 (High) (GitHub Advisory, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning GLPI fails to properly sanitize or parameterize user-supplied input before incorporating it into SQL queries. An authenticated, low-privileged user can craft malicious input that alters the intended SQL command sent to the database backend. The attack is network-based, requires no user interaction, and has low attack complexity, making it straightforward to exploit once valid credentials are obtained. No specific vulnerable endpoint or payload details have been publicly disclosed beyond the GitHub advisory (GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary SQL commands against the GLPI database. According to the GitHub advisory, the primary impact is on confidentiality (rated High), with potential exposure of sensitive data such as user credentials, asset inventory, and IT management records stored in the database. The NVD assessment additionally rates integrity and availability impacts as High, suggesting the possibility of data modification or service disruption depending on database configuration and permissions (GitHub Advisory, Red Hat CVE).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (Red Hat CVE). The EPSS score is approximately 0.035%, indicating a low current probability of exploitation in the wild. No threat actor attribution has been identified, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was detected by Nessus plugin 302999, enabling automated scanning for affected instances (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify GLPI instances running versions 11.0.0–11.0.5 using web application fingerprinting tools (e.g., Shodan, Censys) or by checking the GLPI version disclosure on the login page.
  2. Authentication: Obtain valid low-privileged GLPI credentials through phishing, credential stuffing, or other means, as the vulnerability requires authentication.
  3. Identify injectable parameter: Interact with GLPI's authenticated features (e.g., search, asset management, or reporting functions) and identify input fields or API parameters that are passed to SQL queries without proper sanitization.
  4. Craft SQL injection payload: Inject SQL syntax (e.g., ' OR 1=1--, UNION-based, or blind time-based payloads) into the vulnerable parameter to manipulate the underlying database query.
  5. Extract sensitive data: Use the SQL injection to enumerate database tables and extract sensitive information such as user credentials, session tokens, or asset data from the GLPI database.
  6. Escalate or pivot: Use extracted credentials or session data to escalate privileges within GLPI or pivot to other systems in the environment (GitHub Advisory).

Indicators of compromise

  • Network: Unusual or malformed HTTP requests to GLPI endpoints containing SQL metacharacters (e.g., single quotes ', --, UNION, SELECT, OR 1=1) in query parameters or POST body fields.
  • Logs: GLPI application or web server access logs showing repeated requests with anomalous parameter values; database error messages logged indicating malformed SQL queries.
  • Database: Unexpected or unauthorized queries in database query logs (e.g., MySQL general query log) involving UNION SELECT statements or time-delay functions (e.g., SLEEP(), BENCHMARK()).
  • Process: Unusual database activity such as large data exports, unexpected table reads, or queries accessing credential-related tables (e.g., glpi_users) from the GLPI application account.

Mitigation and workarounds

The primary remediation is to upgrade GLPI to version 11.0.6 or later, which was released and patched on March 19, 2026 (GitHub Advisory). All instances running versions 11.0.0 through 11.0.5 should be prioritized for immediate patching. As interim mitigations, administrators should restrict GLPI access to trusted networks using firewall rules or VPN, enforce the principle of least privilege for GLPI user accounts, and monitor authentication and database logs for anomalous activity. Questions about the advisory can be directed to glpi-security@ow2.org (GitHub Advisory).

Community reactions

The vulnerability was reported by the security researcher "login-securite" and disclosed via GitHub's security advisory program. Coverage has been limited to vulnerability aggregator sites such as CVEfeed, VulDB, CIRCL, and ENISA's EUVD, with no notable independent researcher commentary or significant social media discussion identified at this time (GitHub Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Ubuntu

Unknown

xenial (esm-apps-legacy)

glpi

Unknown

Source: This report was generated using AI

Related GLPI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55214HIGH8.5
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53629HIGH7.1
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53627MEDIUM6
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53628MEDIUM5.9
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-55217MEDIUM5.3
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management