Executive brief
GLPI is an open-source IT asset management and service desk platform used by organizations to track hardware, software, and support tickets. A security vulnerability allows users with technician-level privileges to access and read sensitive files stored within the application's document directory that they should not be able to see. This could lead to the exposure of internal documentation, configuration details, or other sensitive business data managed within the system.
Technical details
A missing authorization vulnerability (CWE-862) in GLPI allows an authenticated user with 'technician' privileges to access arbitrary files within the GLPI_DOC_DIR directory. The vulnerability stems from insufficient access control checks when retrieving documents. An attacker must have high-level (technician) privileges and navigate high attack complexity to successfully exploit this flaw. Successful exploitation results in a high confidentiality impact as the attacker can read sensitive files stored on the server, though it does not allow for file modification or service disruption. The issue is resolved in versions 10.0.25 and 11.0.7.
Affected products
- Teclib' GLPI >= 0.50, < 10.0.25; >= 11.0.0, < 11.0.7
Timeline
- 2026-05-18: advisory: Vendor advisory published on GitHub
- 2026-06-03: disclosed: CVE published in NVD