CVE-2026-22821: mreporting affected by a SQLI on date change
Published Feb 12, 2026
·Updated
mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vulnerability is fixed in 1.9.4.
Affected Software
2 affected components
glpi/mreporting<1.9.4
GLPI-PROJECT More Reporting Glpi<1.9.4
Remediation
Event History
Feb 12, 2026
CVE Published
via MITRE·06:43 PM
Data Sourced
via MITRE·06:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-22821?
CVE-2026-22821 has a high severity due to the potential for SQL injection attacks affecting data integrity and security.
2
How do I fix CVE-2026-22821?
To fix CVE-2026-22821, upgrade to mreporting version 1.9.4 or later.
3
What software is affected by CVE-2026-22821?
CVE-2026-22821 affects the mreporting plugin for GLPI prior to version 1.9.4.
4
Can CVE-2026-22821 lead to data breaches?
Yes, CVE-2026-22821 could potentially lead to data breaches if exploited through SQL injection.
5
Is there a known exploit for CVE-2026-22821?
There are no public exploits reported for CVE-2026-22821; however, the vulnerability should be remediated to prevent any potential attacks.