CVE-2026-55217

medium

Description

GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete knowledge base comments and translations without the required authorization for the affected content. This issue is fixed in versions 11.0.8 and 10.0.26.

References

https://github.com/glpi-project/glpi/security/advisories/GHSA-xm3v-3g6q-g9q8

https://github.com/glpi-project/glpi/releases/tag/11.0.8

https://github.com/glpi-project/glpi/releases/tag/10.0.26

https://github.com/glpi-project/glpi/commit/9c29f25bd09eca9e62ca50c52b3ebd15b02997b2

https://github.com/glpi-project/glpi/commit/1cbf69b99dfd0610f1c03a3f245f3b248e1bfde0

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87280

Details

Source: Mitre, NVD

Published: 2026-09-25

Updated: 2026-09-25

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Severity: Medium

CVSS v4

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00313