CVE-2026-25937: GLPI has a MFA bypass
Published Mar 17, 2026
·Updated
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malicious actor with knowledge of a user's credentials can bypass MFA and steal their account. Version 11.0.6 fixes the issue.
Affected Software
2 affected components
glpi/glpi>=11.0.0<11.0.6
Teclib-edition Glpi>=11.0.0<11.0.6
Event History
Mar 17, 2026
CVE Published
via MITRE·11:16 PM
Data Sourced
via MITRE·11:16 PM
DescriptionSeverityWeakness
Mar 18, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-25937?
CVE-2026-25937 is classified as a high severity vulnerability due to its potential for unauthorized account access.
2
How do I fix CVE-2026-25937?
To fix CVE-2026-25937, upgrade GLPI to version 11.0.6 or later.
3
What specifically does CVE-2026-25937 allow an attacker to do?
CVE-2026-25937 allows an attacker with user credentials to bypass multi-factor authentication (MFA) and take over the account.
4
Which versions of GLPI are affected by CVE-2026-25937?
CVE-2026-25937 affects GLPI versions from 11.0.0 up to but not including 11.0.6.
5
What is GLPI in relation to CVE-2026-25937?
GLPI is an asset and IT management software package that is vulnerable to CVE-2026-25937 regarding its MFA implementation.