Junglewise Threat Intelligence

CVE-2026-13490: glpi-project GLPI authorization bypass in Document Handler

CVE-2026-13490 · Severity: low · CVSS 3.7 · Published 2026-06-28

Executive brief

A security flaw has been identified in GLPI, an open-source asset and IT management software. An unauthorized person could potentially view files they are not supposed to access by manipulating document identifiers. While the impact is limited to viewing certain data, it could lead to the exposure of sensitive internal documentation or attachments.

Technical details

An authorization bypass vulnerability exists in GLPI versions 11.0.5, 11.0.6, and 11.0.7 within the Document Handler component. The flaw is located in the Document::canViewFile function in front/document.send.php and is triggered by manipulating the 'docid' parameter (CWE-639). A remote attacker can exploit this to bypass access controls and view files without proper authorization. The attack is considered high complexity and difficult to exploit, likely requiring specific preconditions or knowledge of document identifiers. The vulnerability was reported via VulDB and the vendor was notified prior to disclosure.

Affected products

  • glpi-project GLPI 11.0.5, 11.0.6, 11.0.7

Timeline

  • 2026-06-28: disclosed
  • 2026-06-28: advisory

References