CVE-2026-42320
GLPI vulnerability analysis and mitigation

Overview

CVE-2026-42320 is an arbitrary file read vulnerability in GLPI, a free open-source IT asset management platform. Starting from version 0.50 and prior to versions 10.0.25 (10.x branch) and 11.0.7 (11.x branch), an authenticated technician-level user can read arbitrary files within the GLPI_DOC_DIR directory without proper authorization. The vulnerability was published on June 3, 2026, with the GitHub Security Advisory (GHSA-58j6-94cf-gcx5) originally published May 18, 2026. It carries a CVSS v4.0 base score of 5.9 (Medium) (GitHub Advisory, ENISA EUVD).

Technical details

The root cause is classified as CWE-862 (Missing Authorization) — the application fails to enforce adequate access controls when a technician-level user requests files stored within the GLPI_DOC_DIR directory. An attacker with a valid technician account can craft requests to access files they are not authorized to read, bypassing the intended permission model. The attack vector is network-based, requires high privileges (technician role), and has high attack complexity, meaning some non-trivial conditions must be met for exploitation. The vulnerability was reported by researcher HuajiHD (GitHub Advisory).

Impact

Successful exploitation allows an authenticated technician to read arbitrary files stored within the GLPI_DOC_DIR directory, resulting in a high confidentiality impact on the vulnerable system. This could expose sensitive documents, attachments, or other files managed by GLPI — such as IT asset records, contracts, or internal documentation — that the technician is not authorized to access. There is no integrity or availability impact, and the vulnerability does not affect systems beyond the GLPI application itself (GitHub Advisory, ENISA EUVD).

Exploitation steps

  1. Obtain Technician Credentials: Acquire a valid GLPI technician-level account, either through legitimate access, credential theft, or social engineering.
  2. Identify Vulnerable Instance: Confirm the target GLPI instance is running a version >= 0.50 and < 10.0.25 (10.x branch) or >= 11.0.0 and < 11.0.7 (11.x branch).
  3. Craft Malicious Request: As an authenticated technician, craft an HTTP request targeting the GLPI functionality that handles document or file access, manipulating file path parameters to reference files within GLPI_DOC_DIR that the technician account should not be permitted to access.
  4. Read Arbitrary Files: Submit the crafted request; due to the missing authorization check, the server returns the contents of the targeted file, exposing sensitive documents stored in the GLPI document directory (GitHub Advisory).

Indicators of compromise

  • Logs: GLPI application logs showing technician-level accounts accessing document or file endpoints for files outside their assigned scope; repeated or unusual file access patterns from a single technician account.
  • Network: HTTP requests from authenticated technician sessions targeting document retrieval endpoints with unexpected or traversal-style file path parameters.
  • Application: Access to files in GLPI_DOC_DIR by technician accounts that do not have a documented business need for those specific files; audit log entries for file reads not correlated with open tickets or assigned assets.

Mitigation and workarounds

GLPI has released patched versions to address this vulnerability: 10.0.25 for the 10.x branch and 11.0.7 for the 11.x branch. Organizations should upgrade to one of these versions as the primary remediation. No official configuration-based workaround has been published; therefore, upgrading is the only recommended mitigation. For questions or concerns, GLPI's security team can be contacted at glpi-security@ow2.org (GitHub Advisory).

Community reactions

The vulnerability was noted in security newsletters and threat intelligence aggregators shortly after disclosure, including coverage in CTI pilot briefs and security news feeds in May 2026. No significant vendor statements beyond the official GitHub Security Advisory have been identified, and there is no notable researcher commentary or social media discussion beyond routine CVE tracking (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related GLPI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-42321HIGH8.4
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026
CVE-2026-44281HIGH7
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026
CVE-2026-42318HIGH7
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026
CVE-2026-13490MEDIUM6.3
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 28, 2026
CVE-2026-42320MEDIUM5.9
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management