CVE-2026-48482 CVE-2026-47679 CVE-2026-55214 CVE-2026-49470 CVE-2026-53610 CVE-2026-53625 CVE-2026-53629 CVE-2026-53626 CVE-2026-53627 CVE-2026-53628
GLPI 11.0.8 fixes remote code execution via Form import and nine further vulnerabilities
GLPI 11.0.8 fixes critical remote code execution through Form import and nine further flaws, including SQL injection, cross-site scripting and TOTP brute-forcing. Upgrade GLPI 11.0 before 11.0.8 to 11.0.8, and GLPI 10.0 before 10.0.26 to 10.0.26.
What happened
GLPI 11.0.8 closes ten security issues. The most severe is CVE-2026-48482, a critical remote code execution flaw in Form import: a user with form administrator rights can import a crafted illustration or scene identifier that escapes the intended custom-asset directory, writes a file to an executable server location, and allows a malicious script to be invoked remotely. It is rated CVSS 4.0 9.4.
The remaining nine issues span file handling, injection, cross-site scripting and authorisation. CVE-2026-47679 lets any logged-in user request deletion of an attacker-selected server file through the profile-picture update flow. CVE-2026-53629 is SQL injection in the history tab, reachable by a user with READ right on logs. CVE-2026-49470 permits brute-forcing of the TOTP second factor once primary credentials are known. The update also addresses stored and reflected cross-site scripting, authtype and entity-scope authorisation bypasses, unallowed API update operations, and arbitrary document read.
The CVE records do not list these issues in CISA KEV, and do not report public disclosure or active exploitation.
Who is affected
GLPI is a self-hosted IT asset and service management package, typically used for helpdesk, asset inventory and change management. The affected product is self-hosted GLPI.
The critical form import flaw, the TOTP brute-force issue, the reflected XSS, the API update issue and several other defects affect GLPI from 11.0.0 until 11.0.8. The stored XSS issue affects GLPI from 11.0.6 until 11.0.8; the arbitrary document read issue affects GLPI from 11.0.5 until 11.0.8.
Four issues also affect the 10.0 line or older branches: arbitrary file deletion from 10.0.0 until 10.0.26, authtype privilege escalation from 0.70 until 10.0.26, SQL injection from 9.4.0 until 10.0.26, and the unallowed authentication method update from 0.84 until 10.0.26. The fixed release for the 10.0 line is 10.0.26.
What to do now
- Confirm your installed GLPI version. If you run GLPI 11.0 before 11.0.8, upgrade to 11.0.8. If you run GLPI 10.0 before 10.0.26, upgrade to 10.0.26.
- Prioritise any internet-facing GLPI web interface or API, because the most severe issues are reachable over the network.
- The GLPI advisory does not list workarounds. If you cannot upgrade immediately, restrict access to the GLPI web interface and API to trusted management networks. Keep MFA enabled where possible, but be aware that CVE-2026-49470 weakens TOTP protection for accounts whose primary credentials are already compromised.
- After upgrading, review highly privileged accounts, authentication methods and API permissions for changes you did not authorise.
Beyond the patch
GLPI is often treated as internal plumbing, but this update shows why it needs the same patch discipline and control testing as any externally supplied platform. Our Implementation & Assessment Services can penetration-test and harden GLPI before the next update, and Supply Chain Defense & Third-Party Risk helps you track which versions of GLPI and other software you run and how quickly you close their exposure windows.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-48482, CVE-2026-49470, CVE-2026-53610, CVE-2026-53627 glpi | >= 11.0.0, < 11.0.8 | .8 |
| CVE-2026-47679 glpi | >= 10.0.0, < 10.0.26 >= 11.0.0, < 11.0.8 | .26, 11.0.8 |
| CVE-2026-55214 glpi | >= 11.0.6, < 11.0.8 | .8 |
| CVE-2026-53625 glpi | >= 0.70, < 10.0.26 >= 11.0.0, < 11.0.8 | .26, 11.0.8 |
| CVE-2026-53629 glpi | >= 9.4.0, < 10.0.26 >= 11.0.0, < 11.0.8 | .26, 11.0.8 |
| CVE-2026-53626 glpi | >= 11.0.5, < 11.0.8 | .8 |
| CVE-2026-53628 glpi | >= 0.84, < 10.0.26 >= 11.0.0, < 11.0.8 | .26, 11.0.8 |
References
Vendor advisory
Other
- github.com/glpi-project/glpi/commit/d817cb5c17e3368c89d4a561a43a777662b9da19
- github.com/glpi-project/glpi/releases/tag/11.0.8
- github.com/glpi-project/glpi/commit/54306faf6a724321ba82c53c7c07ff6612a0d832
- github.com/glpi-project/glpi/commit/78ec583051bac3c1b3f9d21729c55cac62afa2f3
- github.com/glpi-project/glpi/releases/tag/10.0.26
- github.com/glpi-project/glpi/commit/970786ed3b817c4c2bf90b8457b024ec566b1bfc
- github.com/glpi-project/glpi/commit/19a0e81a2b09fee43b3e2a603639fc9b61360c73
- github.com/glpi-project/glpi/commit/9b17a3b2b91070cf197dedae3286322a41c4bc92
CVE
- CVE-2026-48482 — cve.org
- CVE-2026-48482 — NVD
- EUVD-2026-87287 — ENISA EUVD
- CVE-2026-47679 — cve.org
- CVE-2026-47679 — NVD
- EUVD-2026-87284 — ENISA EUVD
- CVE-2026-55214 — cve.org
- CVE-2026-55214 — NVD
- EUVD-2026-87283 — ENISA EUVD
- CVE-2026-49470 — cve.org
- CVE-2026-49470 — NVD
- EUVD-2026-87282 — ENISA EUVD
- CVE-2026-53610 — cve.org
- CVE-2026-53610 — NVD
- EUVD-2026-87285 — ENISA EUVD
- CVE-2026-53625 — cve.org
- CVE-2026-53625 — NVD
- EUVD-2026-87286 — ENISA EUVD
- CVE-2026-53629 — cve.org
- CVE-2026-53629 — NVD
- EUVD-2026-87289 — ENISA EUVD
- CVE-2026-53626 — cve.org
- CVE-2026-53626 — NVD
- EUVD-2026-87288 — ENISA EUVD
- CVE-2026-53627 — cve.org
- CVE-2026-53627 — NVD
- EUVD-2026-87273 — ENISA EUVD
- CVE-2026-53628 — cve.org
- CVE-2026-53628 — NVD
- EUVD-2026-87275 — ENISA EUVD