CVE-2026-42318
GLPI vulnerability analysis and mitigation

Overview

CVE-2026-42318 is a missing authorization vulnerability in GLPI (Gestionnaire Libre de Parc Informatique), a free asset and IT management software package. It allows low-privilege users with access to the planning feature to delete any object within GLPI, regardless of their actual permissions. The vulnerability affects GLPI versions starting from 9.5.0 up to (but not including) 10.0.25 and 11.0.7. It was published on June 3, 2026, with a CVSS v4.0 base score of 7.0 (High) (GitHub Advisory, ENISA EUVD).

Technical details

The root cause is classified as CWE-862 (Missing Authorization) — the application fails to perform proper authorization checks when a user with planning access attempts to delete objects beyond their intended scope (GitHub Advisory). An authenticated attacker (technician-level account with planning access) can exploit this over the network by leveraging the planning feature's delete functionality to target arbitrary GLPI objects, bypassing object-level access controls. No special attack complexity or user interaction is required beyond having a valid low-privilege account with planning rights.

Impact

Successful exploitation allows an authenticated low-privilege user to delete any object managed within GLPI — including assets, tickets, users, and configuration items — causing significant integrity and availability impacts to the IT management platform. This could result in destruction of asset inventory records, loss of helpdesk ticket history, or disruption of IT management workflows. Confidentiality is not directly impacted, as the vulnerability enables deletion rather than data disclosure (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify a GLPI instance running a vulnerable version (>= 9.5.0, < 10.0.25 or >= 11.0.0, < 11.0.7) accessible over the network.
  2. Obtain credentials: Acquire or use an existing low-privilege account (e.g., technician role) that has been granted access to the GLPI planning feature.
  3. Access planning feature: Log in to GLPI and navigate to the Planning module.
  4. Trigger unauthorized deletion: Craft or manipulate a delete request through the planning interface, supplying the ID of an arbitrary GLPI object (e.g., a computer asset, ticket, or user) that the attacker would not normally have permission to delete.
  5. Achieve impact: The missing authorization check allows the deletion request to succeed, removing the targeted object from the GLPI database regardless of the attacker's actual permissions (GitHub Advisory).

Indicators of compromise

  • Logs: GLPI application logs showing delete actions performed by low-privilege or technician accounts on objects outside their normal scope; unexpected deletion events in the GLPI audit/history log for assets, tickets, or users.
  • Application Behavior: Sudden disappearance of GLPI objects (computers, tickets, users, configuration items) without corresponding authorized administrative actions.
  • Network: HTTP DELETE or POST requests to GLPI planning-related endpoints from accounts not expected to perform bulk or cross-scope deletions.

Mitigation and workarounds

Upgrade GLPI to version 10.0.25 (for the 10.x branch) or 11.0.7 (for the 11.x branch) to receive the official patch (GitHub Advisory). As an interim workaround for organizations unable to upgrade immediately, disable delete rights for User's planning within GLPI's permission configuration. Organizations should also audit planning access permissions and restrict them to only users who require this functionality.

Community reactions

The vulnerability was noted in security newsletters and threat intelligence aggregators shortly after disclosure, including coverage in CERT-FR advisory CERTFR-2026-AVI-0551 and monitoring by platforms such as Vulners, VulDB, and CIRCL (owlsnightcatch newsletter). No significant public researcher commentary or social media discussion beyond routine vulnerability tracking has been observed.

Additional resources


SourceThis report was generated using AI

Related GLPI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-42321HIGH8.4
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026
CVE-2026-44281HIGH7
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026
CVE-2026-42318HIGH7
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026
CVE-2026-13490MEDIUM6.3
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 28, 2026
CVE-2026-42320MEDIUM5.9
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management