CVE-2026-26001: GLPI Inventory Plugin has SQL Injection on dropdown_calendar Report
Published Mar 17, 2026
·Updated
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, non sanitized user input can lend to an SQL injection from reports, with adequate rights. This vulnerability is fixed in 1.6.6.
Affected Software
2 affected components
GLPI GLPI Inventory Plugin<1.6.6
GLPI-PROJECT Glpi Inventory<1.6.6
Event History
Mar 17, 2026
CVE Published
via MITRE·11:18 PM
Data Sourced
via MITRE·11:18 PM
DescriptionSeverityWeakness
Mar 18, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-26001?
CVE-2026-26001 is rated as a high severity SQL injection vulnerability that can affect the GLPI Inventory Plugin.
2
How do I fix CVE-2026-26001?
To mitigate CVE-2026-26001, upgrade the GLPI Inventory Plugin to version 1.6.6 or later.
3
Who is affected by CVE-2026-26001?
CVE-2026-26001 affects users of GLPI Inventory Plugin versions prior to 1.6.6.
4
What type of vulnerability is CVE-2026-26001?
CVE-2026-26001 is an SQL injection vulnerability resulting from non-sanitized user input.
5
What can an attacker do with CVE-2026-26001?
An attacker with adequate rights can exploit CVE-2026-26001 to execute arbitrary SQL queries through reports.