CVE-2026-13490: glpi-project glpi Document document.send.php canViewFile authorization
A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document::canViewFile of the file front/document.send.php of the component Document Handler. Such manipulation of the argument docid leads to authorization bypass. The attack can be executed remotely. This attack is characterized by high complexity. It is indicated that the exploitability is difficult. The vendor was contacted early about this disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13490?
The severity of CVE-2026-13490 is classified as low with a score of 3.7.
What is CVE-2026-13490 related to?
CVE-2026-13490 is related to an authorization bypass vulnerability in the Document Handler of glpi-project GLPI.
How do I fix CVE-2026-13490?
To fix CVE-2026-13490, it is recommended to upgrade GLPI to the latest version where the vulnerability is patched.
What impact does CVE-2026-13490 have?
CVE-2026-13490 potentially allows unauthorized access to sensitive documents through manipulation of the docid argument.
Which versions of GLPI are affected by CVE-2026-13490?
CVE-2026-13490 affects glpi-project GLPI versions 11.0.5, 11.0.6, and 11.0.7.