CVE-2026-29047: GLPI has an Authenticated SQL Injection via log exports
GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection via the logs export feature. This vulnerability is fixed in 10.0.24 and 11.0.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29047?
CVE-2026-29047 has a medium severity rating due to its potential for exploitation through authenticated SQL injection.
How do I fix CVE-2026-29047?
To fix CVE-2026-29047, upgrade your GLPI installation to version 10.0.24 or 11.0.6 or later.
Who is affected by CVE-2026-29047?
CVE-2026-29047 affects versions of GLPI from 10.0.0 to before 10.0.24 and from 11.0.0 to before 11.0.6.
What types of attacks can CVE-2026-29047 enable?
CVE-2026-29047 can enable authenticated SQL injection attacks, potentially allowing unauthorized access to database information.
Is there a workaround for CVE-2026-29047?
There is no official workaround for CVE-2026-29047, and it is recommended to upgrade to a fixed version to mitigate the risk.