
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-42320 is an arbitrary file read vulnerability in GLPI, a free open-source IT asset management platform. Starting from version 0.50 and prior to versions 10.0.25 (10.x branch) and 11.0.7 (11.x branch), an authenticated technician-level user can read arbitrary files within the GLPI_DOC_DIR directory without proper authorization. The vulnerability was published on June 3, 2026, with the GitHub Security Advisory (GHSA-58j6-94cf-gcx5) originally published May 18, 2026. It carries a CVSS v4.0 base score of 5.9 (Medium) (GitHub Advisory, ENISA EUVD).
The root cause is classified as CWE-862 (Missing Authorization) — the application fails to enforce adequate access controls when a technician-level user requests files stored within the GLPI_DOC_DIR directory. An attacker with a valid technician account can craft requests to access files they are not authorized to read, bypassing the intended permission model. The attack vector is network-based, requires high privileges (technician role), and has high attack complexity, meaning some non-trivial conditions must be met for exploitation. The vulnerability was reported by researcher HuajiHD (GitHub Advisory).
Successful exploitation allows an authenticated technician to read arbitrary files stored within the GLPI_DOC_DIR directory, resulting in a high confidentiality impact on the vulnerable system. This could expose sensitive documents, attachments, or other files managed by GLPI — such as IT asset records, contracts, or internal documentation — that the technician is not authorized to access. There is no integrity or availability impact, and the vulnerability does not affect systems beyond the GLPI application itself (GitHub Advisory, ENISA EUVD).
GLPI has released patched versions to address this vulnerability: 10.0.25 for the 10.x branch and 11.0.7 for the 11.x branch. Organizations should upgrade to one of these versions as the primary remediation. No official configuration-based workaround has been published; therefore, upgrading is the only recommended mitigation. For questions or concerns, GLPI's security team can be contacted at glpi-security@ow2.org (GitHub Advisory).
The vulnerability was noted in security newsletters and threat intelligence aggregators shortly after disclosure, including coverage in CTI pilot briefs and security news feeds in May 2026. No significant vendor statements beyond the official GitHub Security Advisory have been identified, and there is no notable researcher commentary or social media discussion beyond routine CVE tracking (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."