Junglewise Threat Intelligence

CVE-2026-40108: GLPI stored XSS in ITIL costs

CVE-2026-40108 · Severity: info · CVSS 7.1 · Published 2026-06-02

Technologies: GLPI Project GLPI. Vendors: GLPI Project.

Executive brief

GLPI is an open-source IT asset and service management platform used by organizations to track hardware, software, and support tickets. A security vulnerability in the ITIL costs component allows a technician to inject malicious scripts into the system. If another user views the affected cost records, the script could execute in their browser, potentially leading to unauthorized data access or administrative actions.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in GLPI versions 11.0.0 through 11.0.6 within the ITIL costs management component. The root cause is improper neutralization of user-controllable input (CWE-79) before it is rendered in the web interface. An attacker with high-level technician privileges can inject a malicious payload into cost records. Execution of the payload requires a victim (such as another administrator) to interact with the affected page. Successful exploitation can result in a full compromise of the user's session, impacting confidentiality, integrity, and availability. The issue is addressed in version 11.0.7.

Affected products

  • glpi-project GLPI 11.0.0 to 11.0.6

Timeline

  • 2026-06-01: advisory: GitHub Security Advisory published by the vendor.
  • 2026-06-02: disclosed: CVE published to the NVD.
  • 2026-06-02: patched: Fix released in version 11.0.7.

References