CVE-2026-29047: 
GLPI vulnerability analysis and mitigation

Overview

CVE-2026-29047 is an authenticated SQL injection vulnerability in GLPI, a free open-source asset and IT management software package. It affects GLPI versions 10.0.0 through 10.0.23 and 11.0.0 through 11.0.5, and was published on April 6, 2026. The vulnerability was fixed in versions 10.0.24 and 11.0.6. It carries a CVSS v3.1 base score of 7.2 (High) per the official GitHub Security Advisory, though NVD scores it at 8.8 (High) due to differing privilege-required assessments (GitHub Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input passed to the logs export feature is not properly sanitized before being incorporated into SQL queries. An authenticated attacker can craft malicious input through the logs export functionality to manipulate the underlying SQL command executed by the database. The attack vector is network-based, requires low attack complexity, and no user interaction, though it does require authentication. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, Feedly).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary SQL commands against the GLPI database, resulting in high impact to confidentiality, integrity, and availability. An attacker could read sensitive IT asset management data (including organizational assets, configurations, and user records), modify or delete database records, or potentially disrupt the availability of the GLPI instance. Depending on database server configuration and privileges, exploitation could also enable command execution at the operating system level via database features (GitHub Advisory, Feedly).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.028%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authentication, which somewhat limits the attack surface, though low-privilege authenticated users may be sufficient depending on GLPI role configurations.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible GLPI instances running versions 10.0.0–10.0.23 or 11.0.0–11.0.5 using network scanning or web application fingerprinting tools.
  2. Authentication: Obtain valid GLPI credentials — even a low-privilege user account may be sufficient depending on access to the logs export feature.
  3. Access the logs export feature: Navigate to the GLPI logs export functionality within the application interface.
  4. Inject malicious SQL payload: Craft and submit input containing SQL injection syntax (e.g., ' OR 1=1--, UNION-based, or time-based blind payloads) within the export parameters to manipulate the underlying SQL query.
  5. Extract or manipulate data: Depending on the injection type, enumerate database tables, extract sensitive records (user credentials, asset data), modify records, or attempt to escalate privileges within the database (GitHub Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to GLPI log export endpoints containing SQL metacharacters (e.g., single quotes, UNION, SELECT, --, OR 1=1) in request parameters.
  • Logs: GLPI application logs or web server access logs showing anomalous export requests with encoded or obfuscated SQL syntax; database error messages logged in GLPI error logs indicating malformed queries.
  • Database: Unexpected queries in database slow query logs or general query logs originating from the GLPI application user, particularly those involving UNION SELECT, information_schema, or unusual table reads.
  • Application: Unexpected data exports or large result sets returned from the logs export feature; access to the logs export feature by accounts not typically associated with administrative tasks.

Mitigation and workarounds

The GLPI project has released patched versions addressing this vulnerability: upgrade to 10.0.24 (for the 10.0.x branch) or 11.0.6 (for the 11.0.x branch). Until patching is possible, restrict access to the logs export feature to only the most trusted administrators, implement network-level access controls to limit exposure of the GLPI application, and monitor database activity logs for suspicious SQL queries. Reviewing recent export operations for signs of unauthorized data access is also recommended (GitHub Advisory, Feedly).

Community reactions

The vulnerability was credited to researchers UncleJ4ck and Shakun8, who reported it to the GLPI security team. The advisory was published by the GLPI project on April 3, 2026, and the CVE was formally published on April 6, 2026. The CISA vulnerability bulletin for the week of April 6, 2026 referenced this CVE, and it was picked up by security aggregators including Tenable (Nessus plugin 305608) and VulDB (GitHub Advisory, Feedly).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Ubuntu

Unknown

xenial (esm-apps-legacy)

glpi

Unknown

Source: This report was generated using AI

Related GLPI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55214HIGH8.5
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53629HIGH7.1
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53627MEDIUM6
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53628MEDIUM5.9
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-55217MEDIUM5.3
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management