
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25936 is an authenticated SQL injection vulnerability in GLPI, a free Asset and IT management software package developed by Teclib. It affects GLPI versions 11.0.0 through 11.0.5, and was patched in version 11.0.6. The vulnerability was published on March 17, 2026, and was reported by the security researcher "login-securite." The GitHub Security Advisory assigns a CVSS v3.1 score of 6.5 (Moderate), while NVD rates it 8.8 (High) (GitHub Advisory, Red Hat CVE).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning GLPI fails to properly sanitize or parameterize user-supplied input before incorporating it into SQL queries. An authenticated, low-privileged user can craft malicious input that alters the intended SQL command sent to the database backend. The attack is network-based, requires no user interaction, and has low attack complexity, making it straightforward to exploit once valid credentials are obtained. No specific vulnerable endpoint or payload details have been publicly disclosed beyond the GitHub advisory (GitHub Advisory).
Successful exploitation allows an authenticated attacker to execute arbitrary SQL commands against the GLPI database. According to the GitHub advisory, the primary impact is on confidentiality (rated High), with potential exposure of sensitive data such as user credentials, asset inventory, and IT management records stored in the database. The NVD assessment additionally rates integrity and availability impacts as High, suggesting the possibility of data modification or service disruption depending on database configuration and permissions (GitHub Advisory, Red Hat CVE).
As of the time of reporting, there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (Red Hat CVE). The EPSS score is approximately 0.035%, indicating a low current probability of exploitation in the wild. No threat actor attribution has been identified, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was detected by Nessus plugin 302999, enabling automated scanning for affected instances (GitHub Advisory).
' OR 1=1--, UNION-based, or blind time-based payloads) into the vulnerable parameter to manipulate the underlying database query.', --, UNION, SELECT, OR 1=1) in query parameters or POST body fields.SLEEP(), BENCHMARK()).glpi_users) from the GLPI application account.The primary remediation is to upgrade GLPI to version 11.0.6 or later, which was released and patched on March 19, 2026 (GitHub Advisory). All instances running versions 11.0.0 through 11.0.5 should be prioritized for immediate patching. As interim mitigations, administrators should restrict GLPI access to trusted networks using firewall rules or VPN, enforce the principle of least privilege for GLPI user accounts, and monitor authentication and database logs for anomalous activity. Questions about the advisory can be directed to glpi-security@ow2.org (GitHub Advisory).
The vulnerability was reported by the security researcher "login-securite" and disclosed via GitHub's security advisory program. Coverage has been limited to vulnerability aggregator sites such as CVEfeed, VulDB, CIRCL, and ENISA's EUVD, with no notable independent researcher commentary or significant social media discussion identified at this time (GitHub Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."