CVE-2026-49469

medium

Description

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP filter. This allows access to LDAP objects that the default filter was intended to exclude. This issue is fixed in versions 11.0.8 and 10.0.26.

References

https://github.com/glpi-project/glpi/security/advisories/GHSA-3cgm-rj32-hfwf

https://github.com/glpi-project/glpi/releases/tag/11.0.8

https://github.com/glpi-project/glpi/releases/tag/10.0.26

https://github.com/glpi-project/glpi/commit/d413b48ea97b2f73ba30c90ae0d029aac860f71a

https://github.com/glpi-project/glpi/commit/4fb3056bcd292b515acce96887f1376ce6d5aba8

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87272

Details

Source: Mitre, NVD

Published: 2026-09-25

Updated: 2026-09-29

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 8.1

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Severity: High

CVSS v4

Base Score: 4.6

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00398