
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26026 is a Server-Side Template Injection (SSTI) vulnerability in GLPI, a free open-source asset and IT management software package. It affects GLPI versions 11.0.0 through 11.0.5, allowing an authenticated administrator to inject malicious template expressions that lead to Remote Code Execution (RCE). The vulnerability was published on April 6, 2026, and patched in version 11.0.6. It carries a CVSS v3.1 base score of 9.1 (Critical) per the GitHub Security Advisory, or 7.2 (High) per NVD scoring (GitHub Advisory, Feedly).
The root cause is classified under CWE-94 (Improper Control of Generation of Code / Code Injection) and CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine). An authenticated administrator can craft malicious input that is processed by GLPI's template engine without proper sanitization, causing the engine to interpret attacker-controlled content as executable template expressions or code directives. This results in server-side code execution in the context of the GLPI application. The vulnerability was credited to BZHunt Analyst (GitHub Advisory).
Successful exploitation allows an authenticated administrator to execute arbitrary code on the GLPI server, resulting in HIGH impact to confidentiality, integrity, and availability. An attacker could gain full control of the GLPI instance, access sensitive IT asset data and records, modify or destroy data, and potentially pivot to other systems within the network. The GitHub advisory rates the scope as "Changed," indicating that the impact can extend beyond the vulnerable GLPI component itself (GitHub Advisory).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). Exploitation requires high privileges (administrator-level access), which limits the attack surface compared to unauthenticated vulnerabilities. The EPSS score is approximately 0.044%, reflecting a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection coverage is available via Nessus plugin 305619 (Tenable).
{{ system('id') }} or equivalent syntax for the specific template engine used by GLPI) designed to trigger code execution when the template is rendered.sh, bash, cmd.exe, curl, wget, python) indicating OS command execution via template injection.The vendor has released GLPI version 11.0.6, which fixes this vulnerability; all organizations running versions 11.0.0 through 11.0.5 should upgrade immediately (GitHub Advisory). As interim mitigations, restrict administrative access to GLPI to only trusted personnel and enforce the principle of least privilege for admin accounts. Network segmentation should be applied to limit exposure of the GLPI infrastructure, and administrative activity and audit logs should be monitored for suspicious template-related modifications. Questions or concerns can be directed to the GLPI security team at glpi-security@ow2.org.
The vulnerability received coverage from The Hacker Wire, which published an article titled "GLPI Critical RCE via Administrator Template Injection (CVE-2026-26026)" shortly after disclosure (The Hacker Wire). Social media activity was noted on Mastodon and via CVEnew on Nitter following the advisory publication. Community reaction has been moderate, consistent with a vulnerability requiring high-privilege access and lacking a public PoC.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."