CVE-2026-23489: Fields GLPI plugin vulnerable to RCE in dropdown generation
Published Mar 16, 2026
·Updated
Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdowns. This issue has been patched in version 1.23.3.
Affected Software
2 affected components
GLPI Fields<1.23.3
Teclib-edition Fields Glpi<1.23.3
Event History
Mar 16, 2026
CVE Published
via MITRE·05:12 PM
Data Sourced
via MITRE·05:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-23489?
CVE-2026-23489 has a critical severity rating due to the risk of remote code execution.
2
How do I fix CVE-2026-23489?
To fix CVE-2026-23489, update the GLPI Fields plugin to version 1.23.3 or later.
3
Who is affected by CVE-2026-23489?
Users of the GLPI Fields plugin prior to version 1.23.3 are affected by CVE-2026-23489.
4
What type of vulnerability is CVE-2026-23489?
CVE-2026-23489 is a remote code execution vulnerability.
5
Can CVE-2026-23489 be exploited by unauthorized users?
Yes, CVE-2026-23489 can potentially be exploited by users with permissions to create dropdowns.