CVE-2026-44281
GLPI vulnerability analysis and mitigation

Overview

CVE-2026-44281 is a missing authorization vulnerability in GLPI, a free open-source IT asset and management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user with config READ permission can read a specific asset object they should not have access to. The vulnerability was published on June 3, 2026, and is classified as CWE-862 (Missing Authorization). It carries a CVSS v4.0 base score of 7.0 (High) (Feedly, GitHub Advisory).

Technical details

The root cause is CWE-862 (Missing Authorization) — the application fails to perform a proper authorization check when an authenticated user with config READ permission attempts to access a specific asset object. The vulnerability is exploitable over the network (attack vector: Network) with low attack complexity and no user interaction required, but does require high privileges (authenticated user with config READ permission). The GitHub security advisory (GHSA-prjc-xwmh-rhxw) was published by maintainer cedric-anne and credits reporter HuajiHD for discovery. No public proof-of-concept exploit code has been identified (GitHub Advisory, Feedly).

Impact

Successful exploitation allows an authenticated attacker with config READ permission to read a specific asset object beyond their intended authorization scope, resulting in unauthorized disclosure of asset data. The primary impact is a confidentiality breach affecting IT asset inventory data managed within GLPI. While integrity and availability impacts are noted in the CVSS v4.0 vector, the practical exploitation scenario described in the advisory is limited to unauthorized read access of asset objects (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify a GLPI instance running a vulnerable version (>= 0.78 and < 10.0.25, or >= 11.0.0 and < 11.0.7) accessible over the network.
  2. Authentication: Log in to the GLPI instance using an account that has been granted config READ permission.
  3. Access restricted asset object: Navigate to or craft a direct request to the specific asset object endpoint that lacks proper authorization enforcement.
  4. Read unauthorized data: Retrieve the asset object data that should be restricted beyond the user's normal access scope, obtaining potentially sensitive IT asset information (GitHub Advisory, Feedly).

Indicators of compromise

  • Logs: GLPI application logs showing authenticated requests from users with config READ permission accessing asset object endpoints outside their normal usage patterns; repeated or automated access to specific asset object URLs.
  • Network: HTTP GET requests to GLPI asset object endpoints from accounts that do not typically access those resources; unusual access patterns from low-privilege accounts.
  • Application: Audit trail entries in GLPI showing config READ-permissioned users accessing asset records they are not normally associated with.

Mitigation and workarounds

GLPI has released patched versions 10.0.25 and 11.0.7 to address this vulnerability. Users should upgrade to GLPI 11.0.7 or 10.0.25 as soon as possible. No specific configuration-based workaround has been published; as an interim measure, administrators should review and restrict config READ permissions to only trusted users until the upgrade can be applied. For questions, the GLPI security team can be contacted at glpi-security@ow2.org (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher HuajiHD and disclosed by GLPI maintainer cedric-anne via a GitHub Security Advisory. The advisory was rated "Low" severity by the GLPI project at the time of initial publication, though the CVSS v4.0 score assigned is 7.0 (High). No significant broader media coverage or notable community commentary beyond standard vulnerability aggregator tracking has been identified (GitHub Advisory, Feedly).

Additional resources


SourceThis report was generated using AI

Related GLPI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-42321HIGH8.4
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026
CVE-2026-44281HIGH7
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026
CVE-2026-42318HIGH7
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026
CVE-2026-13490MEDIUM6.3
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 28, 2026
CVE-2026-42320MEDIUM5.9
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management