CVE-2026-25590: GLPI Inventory Plugin has Reflected XSS in task jobs
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, there is a reflected XSS vulnerability in task jobs. This vulnerability is fixed in 1.6.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25590?
CVE-2026-25590 is considered a high severity vulnerability due to the potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2026-25590?
The vulnerability CVE-2026-25590 can be fixed by upgrading the GLPI Inventory Plugin to version 1.6.6 or later.
What are the potential impacts of CVE-2026-25590?
CVE-2026-25590 may allow attackers to inject malicious scripts via task jobs, compromising user sessions and sensitive data.
Which versions of the GLPI Inventory Plugin are affected by CVE-2026-25590?
CVE-2026-25590 affects versions of the GLPI Inventory Plugin prior to 1.6.6.
Is there a workaround for CVE-2026-25590 if I cannot upgrade?
There are no known effective workarounds for CVE-2026-25590, so upgrading is strongly recommended.