Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-26026
GLPI vulnerability analysis and mitigation

Overview

CVE-2026-26026 is a Server-Side Template Injection (SSTI) vulnerability in GLPI, a free open-source asset and IT management software package. It affects GLPI versions 11.0.0 through 11.0.5, allowing an authenticated administrator to inject malicious template expressions that lead to Remote Code Execution (RCE). The vulnerability was published on April 6, 2026, and patched in version 11.0.6. It carries a CVSS v3.1 base score of 9.1 (Critical) per the GitHub Security Advisory, or 7.2 (High) per NVD scoring (GitHub Advisory, Feedly).

Technical details

The root cause is classified under CWE-94 (Improper Control of Generation of Code / Code Injection) and CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine). An authenticated administrator can craft malicious input that is processed by GLPI's template engine without proper sanitization, causing the engine to interpret attacker-controlled content as executable template expressions or code directives. This results in server-side code execution in the context of the GLPI application. The vulnerability was credited to BZHunt Analyst (GitHub Advisory).

Impact

Successful exploitation allows an authenticated administrator to execute arbitrary code on the GLPI server, resulting in HIGH impact to confidentiality, integrity, and availability. An attacker could gain full control of the GLPI instance, access sensitive IT asset data and records, modify or destroy data, and potentially pivot to other systems within the network. The GitHub advisory rates the scope as "Changed," indicating that the impact can extend beyond the vulnerable GLPI component itself (GitHub Advisory).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). Exploitation requires high privileges (administrator-level access), which limits the attack surface compared to unauthenticated vulnerabilities. The EPSS score is approximately 0.044%, reflecting a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection coverage is available via Nessus plugin 305619 (Tenable).

Exploitation steps

  1. Gain Administrator Access: Obtain valid GLPI administrator credentials through phishing, credential stuffing, or insider access, as exploitation requires high-privilege authentication.
  2. Identify Template-Enabled Features: Navigate to GLPI administrative features that support template rendering, such as notification templates, document templates, or other configurable text fields processed by the template engine.
  3. Inject Malicious Template Payload: Insert a Server-Side Template Injection payload into a template field (e.g., {{ system('id') }} or equivalent syntax for the specific template engine used by GLPI) designed to trigger code execution when the template is rendered.
  4. Trigger Template Rendering: Save and trigger the rendering of the malicious template by performing an action that causes GLPI to process the template (e.g., sending a notification, previewing a document, or loading a page that renders the template).
  5. Achieve Remote Code Execution: The template engine processes the injected payload and executes arbitrary OS commands in the context of the GLPI web server process, enabling data exfiltration, reverse shell establishment, or further lateral movement (GitHub Advisory).

Indicators of compromise

  • Logs: GLPI application logs showing unusual template rendering errors or unexpected output from template fields; web server access logs with POST requests to template management endpoints from unexpected IP addresses or at unusual times.
  • Process: Unexpected child processes spawned by the GLPI web server process (e.g., sh, bash, cmd.exe, curl, wget, python) indicating OS command execution via template injection.
  • Network: Outbound connections from the GLPI server to unknown external IP addresses, particularly on non-standard ports, which may indicate reverse shell or data exfiltration activity.
  • File System: New or modified files in the GLPI web root or temporary directories, including web shells or unauthorized scripts; unexpected changes to GLPI configuration files.

Mitigation and workarounds

The vendor has released GLPI version 11.0.6, which fixes this vulnerability; all organizations running versions 11.0.0 through 11.0.5 should upgrade immediately (GitHub Advisory). As interim mitigations, restrict administrative access to GLPI to only trusted personnel and enforce the principle of least privilege for admin accounts. Network segmentation should be applied to limit exposure of the GLPI infrastructure, and administrative activity and audit logs should be monitored for suspicious template-related modifications. Questions or concerns can be directed to the GLPI security team at glpi-security@ow2.org.

Community reactions

The vulnerability received coverage from The Hacker Wire, which published an article titled "GLPI Critical RCE via Administrator Template Injection (CVE-2026-26026)" shortly after disclosure (The Hacker Wire). Social media activity was noted on Mastodon and via CVEnew on Nitter following the advisory publication. Community reaction has been moderate, consistent with a vulnerability requiring high-privilege access and lacking a public PoC.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Ubuntu

Unknown

xenial (esm-apps-legacy)

glpi

Unknown

SourceThis report was generated using AI

Related GLPI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-42321HIGH8.4
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026
CVE-2026-44281HIGH7
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026
CVE-2026-42318HIGH7
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026
CVE-2026-13490MEDIUM6.3
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 28, 2026
CVE-2026-42320MEDIUM5.9
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management