
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-29047 is an authenticated SQL injection vulnerability in GLPI, a free open-source asset and IT management software package. It affects GLPI versions 10.0.0 through 10.0.23 and 11.0.0 through 11.0.5, and was published on April 6, 2026. The vulnerability was fixed in versions 10.0.24 and 11.0.6. It carries a CVSS v3.1 base score of 7.2 (High) per the official GitHub Security Advisory, though NVD scores it at 8.8 (High) due to differing privilege-required assessments (GitHub Advisory, Feedly).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input passed to the logs export feature is not properly sanitized before being incorporated into SQL queries. An authenticated attacker can craft malicious input through the logs export functionality to manipulate the underlying SQL command executed by the database. The attack vector is network-based, requires low attack complexity, and no user interaction, though it does require authentication. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, Feedly).
Successful exploitation allows an authenticated attacker to execute arbitrary SQL commands against the GLPI database, resulting in high impact to confidentiality, integrity, and availability. An attacker could read sensitive IT asset management data (including organizational assets, configurations, and user records), modify or delete database records, or potentially disrupt the availability of the GLPI instance. Depending on database server configuration and privileges, exploitation could also enable command execution at the operating system level via database features (GitHub Advisory, Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.028%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authentication, which somewhat limits the attack surface, though low-privilege authenticated users may be sufficient depending on GLPI role configurations.
' OR 1=1--, UNION-based, or time-based blind payloads) within the export parameters to manipulate the underlying SQL query.UNION, SELECT, --, OR 1=1) in request parameters.UNION SELECT, information_schema, or unusual table reads.The GLPI project has released patched versions addressing this vulnerability: upgrade to 10.0.24 (for the 10.0.x branch) or 11.0.6 (for the 11.0.x branch). Until patching is possible, restrict access to the logs export feature to only the most trusted administrators, implement network-level access controls to limit exposure of the GLPI application, and monitor database activity logs for suspicious SQL queries. Reviewing recent export operations for signs of unauthorized data access is also recommended (GitHub Advisory, Feedly).
The vulnerability was credited to researchers UncleJ4ck and Shakun8, who reported it to the GLPI security team. The advisory was published by the GLPI project on April 3, 2026, and the CVE was formally published on April 6, 2026. The CISA vulnerability bulletin for the week of April 6, 2026 referenced this CVE, and it was picked up by security aggregators including Tenable (Nessus plugin 305608) and VulDB (GitHub Advisory, Feedly).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."