CVE-2026-22044: GLPI is Vulnerable to Authenticated SQL Injection
Published Feb 4, 2026
·Updated
GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can perform a SQL injection. This issue has been patched in version 10.0.23.
Affected Software
2 affected components
glpi/glpi>=0.85<10.0.23
GLPI-PROJECT GLPI>=0.85<10.0.23
Event History
Feb 4, 2026
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Mar 12, 58072
Event
via NVD·02:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-22044?
CVE-2026-22044 is considered a critical severity vulnerability due to the potential for authenticated SQL injection attacks.
2
How do I fix CVE-2026-22044?
To fix CVE-2026-22044, upgrade to GLPI version 10.0.23 or later.
3
Who is affected by CVE-2026-22044?
CVE-2026-22044 affects users of GLPI from version 0.85 to before 10.0.23.
4
What is the nature of the vulnerability described in CVE-2026-22044?
CVE-2026-22044 is an authenticated SQL injection vulnerability that can be exploited by users with valid login credentials.
5
When was CVE-2026-22044 reported and patched?
CVE-2026-22044 was patched in version 10.0.23 of GLPI.