CVE-2026-22247: GLPI is Vulnerable to SSRF via Webhooks
Published Feb 4, 2026
·Updated
GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through the Webhook feature. This issue has been patched in version 11.0.5.
Affected Software
2 affected components
GLPI>=11.0.0<11.0.5
GLPI-PROJECT GLPI>=11.0.0<11.0.5
Event History
Feb 4, 2026
CVE Published
via MITRE·05:10 PM
Data Sourced
via MITRE·05:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-22247?
CVE-2026-22247 is classified as a medium severity vulnerability due to its potential for SSRF attacks.
2
How do I fix CVE-2026-22247?
To fix CVE-2026-22247, upgrade GLPI to version 11.0.5 or later.
3
What software versions are affected by CVE-2026-22247?
CVE-2026-22247 affects GLPI versions from 11.0.0 to before 11.0.5.
4
What is an SSRF vulnerability in the context of CVE-2026-22247?
An SSRF vulnerability allows an attacker to send crafted requests to internal services, potentially exposing sensitive data.
5
Who is impacted by CVE-2026-22247?
Administrators using GLPI versions 11.0.0 to 11.0.4 are impacted by CVE-2026-22247.