
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-44281 is a missing authorization vulnerability in GLPI, a free open-source IT asset and management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user with config READ permission can read a specific asset object they should not have access to. The vulnerability was published on June 3, 2026, and is classified as CWE-862 (Missing Authorization). It carries a CVSS v4.0 base score of 7.0 (High) (Feedly, GitHub Advisory).
The root cause is CWE-862 (Missing Authorization) — the application fails to perform a proper authorization check when an authenticated user with config READ permission attempts to access a specific asset object. The vulnerability is exploitable over the network (attack vector: Network) with low attack complexity and no user interaction required, but does require high privileges (authenticated user with config READ permission). The GitHub security advisory (GHSA-prjc-xwmh-rhxw) was published by maintainer cedric-anne and credits reporter HuajiHD for discovery. No public proof-of-concept exploit code has been identified (GitHub Advisory, Feedly).
Successful exploitation allows an authenticated attacker with config READ permission to read a specific asset object beyond their intended authorization scope, resulting in unauthorized disclosure of asset data. The primary impact is a confidentiality breach affecting IT asset inventory data managed within GLPI. While integrity and availability impacts are noted in the CVSS v4.0 vector, the practical exploitation scenario described in the advisory is limited to unauthorized read access of asset objects (GitHub Advisory, Feedly).
GLPI has released patched versions 10.0.25 and 11.0.7 to address this vulnerability. Users should upgrade to GLPI 11.0.7 or 10.0.25 as soon as possible. No specific configuration-based workaround has been published; as an interim measure, administrators should review and restrict config READ permissions to only trusted users until the upgrade can be applied. For questions, the GLPI security team can be contacted at glpi-security@ow2.org (GitHub Advisory).
The vulnerability was reported by security researcher HuajiHD and disclosed by GLPI maintainer cedric-anne via a GitHub Security Advisory. The advisory was rated "Low" severity by the GLPI project at the time of initial publication, though the CVSS v4.0 score assigned is 7.0 (High). No significant broader media coverage or notable community commentary beyond standard vulnerability aggregator tracking has been identified (GitHub Advisory, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."