
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-42318 is a missing authorization vulnerability in GLPI (Gestionnaire Libre de Parc Informatique), a free asset and IT management software package. It allows low-privilege users with access to the planning feature to delete any object within GLPI, regardless of their actual permissions. The vulnerability affects GLPI versions starting from 9.5.0 up to (but not including) 10.0.25 and 11.0.7. It was published on June 3, 2026, with a CVSS v4.0 base score of 7.0 (High) (GitHub Advisory, ENISA EUVD).
The root cause is classified as CWE-862 (Missing Authorization) — the application fails to perform proper authorization checks when a user with planning access attempts to delete objects beyond their intended scope (GitHub Advisory). An authenticated attacker (technician-level account with planning access) can exploit this over the network by leveraging the planning feature's delete functionality to target arbitrary GLPI objects, bypassing object-level access controls. No special attack complexity or user interaction is required beyond having a valid low-privilege account with planning rights.
Successful exploitation allows an authenticated low-privilege user to delete any object managed within GLPI — including assets, tickets, users, and configuration items — causing significant integrity and availability impacts to the IT management platform. This could result in destruction of asset inventory records, loss of helpdesk ticket history, or disruption of IT management workflows. Confidentiality is not directly impacted, as the vulnerability enables deletion rather than data disclosure (GitHub Advisory).
Upgrade GLPI to version 10.0.25 (for the 10.x branch) or 11.0.7 (for the 11.x branch) to receive the official patch (GitHub Advisory). As an interim workaround for organizations unable to upgrade immediately, disable delete rights for User's planning within GLPI's permission configuration. Organizations should also audit planning access permissions and restrict them to only users who require this functionality.
The vulnerability was noted in security newsletters and threat intelligence aggregators shortly after disclosure, including coverage in CERT-FR advisory CERTFR-2026-AVI-0551 and monitoring by platforms such as Vulners, VulDB, and CIRCL (owlsnightcatch newsletter). No significant public researcher commentary or social media discussion beyond routine vulnerability tracking has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."