Junglewise Threat Intelligence

CVE-2026-44281: Teclib GLPI missing authorization in asset object access

CVE-2026-44281 · Severity: info · CVSS 7 · Published 2026-06-03

Technologies: Teclib GLPI. Vendors: Teclib.

Executive brief

GLPI is an open-source IT asset management and service desk platform used to track hardware, software, and support tickets. A security flaw allows certain authorized users to view sensitive asset information they should not have access to. This could lead to the exposure of internal infrastructure details to users with limited administrative roles.

Technical details

A missing authorization vulnerability (CWE-862) exists in GLPI's asset management component. The flaw allows an authenticated user who possesses 'config READ' permissions to access and read specific asset objects that should otherwise be restricted based on their role. The vulnerability is reachable over the network without user interaction, though it requires high privileges (PR:H) to exploit. Patches are available in versions 10.0.25 and 11.0.7.

Affected products

  • Teclib GLPI >= 0.78, < 10.0.25; >= 11.0.0, < 11.0.7

Timeline

  • 2026-06-01: advisory: GitHub Security Advisory published
  • 2026-06-03: disclosed: CVE published to NVD

References

Related threats