
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25937 is an MFA bypass vulnerability in GLPI, a free Asset and IT management software package. A malicious actor with knowledge of a user's credentials can circumvent Multi-Factor Authentication (MFA) protections and take over the targeted account. The vulnerability affects GLPI versions 11.0.0 through 11.0.5, and was patched in version 11.0.6. It was published on March 17–18, 2026, with a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Red Hat CVE).
The vulnerability is classified as CWE-287 (Improper Authentication), indicating a flaw in how GLPI validates or enforces the MFA step during the authentication flow (GitHub Advisory). An attacker who already possesses valid user credentials can exploit this weakness to bypass the MFA challenge entirely, effectively stealing the account without completing the second authentication factor. The attack is network-based, requires no user interaction, and demands high privileges (i.e., knowledge of a valid user's credentials) as a precondition. No public proof-of-concept exploit code has been identified at this time (Feedly).
Successful exploitation allows an attacker to fully compromise a targeted GLPI user account, bypassing MFA protections that would otherwise prevent unauthorized access. This grants the attacker access to sensitive IT asset and management data stored within GLPI, and may enable modification of system records, configuration changes, or privilege escalation within the application. Availability is not directly impacted, but the high confidentiality and integrity impacts make this a significant risk for organizations relying on GLPI for IT asset management (GitHub Advisory, Feedly).
There is currently no evidence of public proof-of-concept exploit code or active in-the-wild exploitation of CVE-2026-25937 (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.026%, reflecting a low probability of exploitation in the near term. No threat actor attribution has been reported.
The primary remediation is to upgrade GLPI to version 11.0.6 or later, which contains the fix for this vulnerability (GitHub Advisory). For organizations unable to patch immediately, recommended interim measures include restricting GLPI access to trusted networks via firewall or VPN, enforcing strong and unique password policies to reduce credential compromise risk, and actively monitoring authentication logs for suspicious login activity. Questions about the advisory can be directed to glpi-security@ow2.org (GitHub Advisory).
The vulnerability was reported by the security researcher credited as "login-securite" and disclosed by the GLPI project maintainers via GitHub Security Advisories (GitHub Advisory). No significant broader media coverage or notable public researcher commentary beyond the official advisory has been identified at this time.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."