CVE-2026-26263: GLPI has an Unauthenticated SQL Injection via Search engine
Published Apr 6, 2026
·Updated
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6.
Affected Software
1 affected component
GLPI-PROJECT GLPI>=11.0.0<11.0.6
Event History
Apr 6, 2026
CVE Published
via MITRE·02:36 PM
Data Sourced
via MITRE·02:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-26263?
CVE-2026-26263 is classified as a critical severity vulnerability due to its potential for unauthenticated SQL injection.
2
How do I fix CVE-2026-26263?
To fix CVE-2026-26263, upgrade your GLPI installation to version 11.0.6 or later.
3
What versions of GLPI are affected by CVE-2026-26263?
GLPI versions from 11.0.0 up to but not including 11.0.6 are affected by CVE-2026-26263.
4
Can CVE-2026-26263 be exploited remotely?
Yes, CVE-2026-26263 is an unauthenticated SQL injection vulnerability that can be exploited remotely.
5
What impact does CVE-2026-26263 have on GLPI users?
CVE-2026-26263 allows attackers to execute arbitrary SQL queries, potentially compromising the database and sensitive data.