CVE-2026-32312: GLPI: Unauthorized export of form structure
GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthorized forms. This issue has been fixed in version 11.0.7.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 11.0.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32312?
CVE-2026-32312 is considered a medium severity vulnerability due to the potential for unauthorized data exposure.
How do I fix CVE-2026-32312?
To fix CVE-2026-32312, upgrade to GLPI version 11.0.7 or later.
What are the affected versions of GLPI for CVE-2026-32312?
CVE-2026-32312 affects GLPI versions 11.0.0 through 11.0.6.
Who is impacted by CVE-2026-32312?
Authenticated users with forms READ permission in GLPI are impacted by CVE-2026-32312.
What type of vulnerability is CVE-2026-32312?
CVE-2026-32312 is an unauthorized export vulnerability that allows exposure of form structures.