CVE-2026-25937: 
GLPI vulnerability analysis and mitigation

Overview

CVE-2026-25937 is an MFA bypass vulnerability in GLPI, a free Asset and IT management software package. A malicious actor with knowledge of a user's credentials can circumvent Multi-Factor Authentication (MFA) protections and take over the targeted account. The vulnerability affects GLPI versions 11.0.0 through 11.0.5, and was patched in version 11.0.6. It was published on March 17–18, 2026, with a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-287 (Improper Authentication), indicating a flaw in how GLPI validates or enforces the MFA step during the authentication flow (GitHub Advisory). An attacker who already possesses valid user credentials can exploit this weakness to bypass the MFA challenge entirely, effectively stealing the account without completing the second authentication factor. The attack is network-based, requires no user interaction, and demands high privileges (i.e., knowledge of a valid user's credentials) as a precondition. No public proof-of-concept exploit code has been identified at this time (Feedly).

Impact

Successful exploitation allows an attacker to fully compromise a targeted GLPI user account, bypassing MFA protections that would otherwise prevent unauthorized access. This grants the attacker access to sensitive IT asset and management data stored within GLPI, and may enable modification of system records, configuration changes, or privilege escalation within the application. Availability is not directly impacted, but the high confidentiality and integrity impacts make this a significant risk for organizations relying on GLPI for IT asset management (GitHub Advisory, Feedly).

Exploitability

There is currently no evidence of public proof-of-concept exploit code or active in-the-wild exploitation of CVE-2026-25937 (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.026%, reflecting a low probability of exploitation in the near term. No threat actor attribution has been reported.

Exploitation steps

  1. Credential Acquisition: Obtain valid credentials for a GLPI user account through phishing, credential stuffing, password reuse, or other means — this is a prerequisite for exploitation.
  2. Initiate Login: Navigate to the GLPI web interface (versions 11.0.0–11.0.5) and begin the authentication process using the stolen credentials.
  3. Bypass MFA: Exploit the improper authentication flaw (CWE-287) in the MFA enforcement logic to skip or circumvent the MFA challenge step, gaining access without providing the second factor.
  4. Account Takeover: Upon successful bypass, gain full authenticated access to the victim's GLPI account, enabling access to IT asset data, system configurations, and potentially escalating privileges within the application (GitHub Advisory).

Indicators of compromise

  • Logs: Authentication log entries showing successful logins for MFA-enabled accounts without a corresponding MFA verification event; logins from unexpected IP addresses or geolocations for accounts with MFA enabled.
  • Network: Unusual or repeated login attempts to the GLPI web interface from unfamiliar IP addresses, particularly those succeeding without MFA completion.
  • Application Behavior: User sessions initiated for accounts that have MFA configured, but with no MFA challenge recorded in application audit logs; unexpected account activity (data access, configuration changes) outside normal business hours.

Mitigation and workarounds

The primary remediation is to upgrade GLPI to version 11.0.6 or later, which contains the fix for this vulnerability (GitHub Advisory). For organizations unable to patch immediately, recommended interim measures include restricting GLPI access to trusted networks via firewall or VPN, enforcing strong and unique password policies to reduce credential compromise risk, and actively monitoring authentication logs for suspicious login activity. Questions about the advisory can be directed to glpi-security@ow2.org (GitHub Advisory).

Community reactions

The vulnerability was reported by the security researcher credited as "login-securite" and disclosed by the GLPI project maintainers via GitHub Security Advisories (GitHub Advisory). No significant broader media coverage or notable public researcher commentary beyond the official advisory has been identified at this time.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Ubuntu

Unknown

xenial (esm-apps-legacy)

glpi

Unknown

Source: This report was generated using AI

Related GLPI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55214HIGH8.5
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53629HIGH7.1
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53627MEDIUM6
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53628MEDIUM5.9
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-55217MEDIUM5.3
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management