CVE-2026-23624: GLPI is vulnerable to session stealing on externally authenticated user change
GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.0.5, when remote authentication is used, based on SSO variables, a user can steal a GLPI session previously opened by another user on the same machine. This issue has been patched in versions .
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23624?
CVE-2026-23624 has been classified with a severity level that indicates it poses a significant risk due to potential session stealing capabilities.
How do I fix CVE-2026-23624?
To mitigate CVE-2026-23624, upgrade GLPI to version 10.0.23 or later, or version 11.0.5 or later.
Who is affected by CVE-2026-23624?
CVE-2026-23624 affects users of GLPI versions from 0.71 up to but not including 10.0.23, and versions before 11.0.5.
What types of attacks are possible due to CVE-2026-23624?
CVE-2026-23624 allows for session stealing attacks that can compromise user accounts in GLPI when using remote authentication.
What is the impact of CVE-2026-23624?
The impact of CVE-2026-23624 can result in unauthorized access to user sessions, potentially leading to data breaches within GLPI.