CVE-2026-25936: GLPI Vulnerable to Authenticated SQL Injection
Published Mar 17, 2026
·Updated
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a SQL injection. Version 11.0.6 fixes the issue.
Affected Software
2 affected components
glpi/glpi>=11.0.0<11.0.6
Teclib-edition Glpi>11.0.0<=11.0.6
Event History
Mar 17, 2026
CVE Published
via MITRE·07:41 PM
Data Sourced
via MITRE·07:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-25936?
CVE-2026-25936 is classified as a high severity vulnerability due to the potential for authenticated SQL injection.
2
How do I fix CVE-2026-25936?
To fix CVE-2026-25936, upgrade your GLPI installation to version 11.0.6 or later.
3
What software versions are affected by CVE-2026-25936?
CVE-2026-25936 affects GLPI versions from 11.0.0 to 11.0.5.
4
What kind of attack does CVE-2026-25936 enable?
CVE-2026-25936 enables authenticated users to perform SQL injection attacks.
5
Can CVE-2026-25936 be exploited remotely?
No, CVE-2026-25936 requires authenticated access, meaning the attacker must already have user credentials.