CVE-2026-26026: GLPI has a Server-Side Template Injection via Double-Compilation
Published Apr 6, 2026
·Updated
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6.
Affected Software
1 affected component
GLPI-PROJECT GLPI>=11.0.0<11.0.6
Event History
Apr 6, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-26026?
CVE-2026-26026 has a critical severity rating due to the potential for remote code execution.
2
How do I fix CVE-2026-26026?
To fix CVE-2026-26026, upgrade GLPI to version 11.0.6 or later.
3
What versions of GLPI are affected by CVE-2026-26026?
GLPI versions from 11.0.0 to before 11.0.6 are affected by CVE-2026-26026.
4
Can CVE-2026-26026 be exploited remotely?
Yes, CVE-2026-26026 can be exploited remotely by an administrator leading to potential remote code execution.
5
What type of vulnerability is CVE-2026-26026?
CVE-2026-26026 is a server-side template injection vulnerability.