Executive brief
GLPI is an open-source IT asset management and service desk platform used by organizations to track hardware, software, and support tickets. A security flaw in certain versions allows authorized users to export the internal structure of forms they are not supposed to access. While this does not expose user data directly, it reveals how internal forms are built, which could be used to plan more sophisticated attacks or bypass business logic.
Technical details
A missing authorization vulnerability (CWE-862) exists in GLPI versions 11.0.0 through 11.0.6. The flaw allows an authenticated user who has been granted 'READ' permissions for forms to bypass intended access controls and export the configuration/structure of forms they are not authorized to view. The attack is carried out over the network and requires high privileges (PR:H) but no user interaction. This exposure results in a loss of confidentiality regarding the system's internal form architecture. The issue is resolved in GLPI version 11.0.7.
Affected products
- GLPI Project GLPI 11.0.0 through 11.0.6
Timeline
- 2026-04-29: patched: Version 11.0.7 released
- 2026-05-18: advisory: GitHub Security Advisory published
- 2026-05-19: disclosed: CVE published in NVD