CVE-2026-40108: GLPI Vulnerable to Stored XSS in ITIL Costs
Published Jun 2, 2026
·Updated
GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XSS payload in a ITIL costs. This issue has been fixed in version 11.0.7.
Affected Software
1 affected component
GLPI GLPI>=11.0.0<=11.0.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 11.0.7
Event History
Jun 2, 2026
CVE Published
via MITRE·11:02 PM
Data Sourced
via MITRE·11:02 PM
DescriptionWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-40108?
CVE-2026-40108 has a high severity rating of 7.1.
2
How do I fix CVE-2026-40108?
To fix CVE-2026-40108, upgrade GLPI to version 11.0.7 or later.
3
What types of attacks are possible with CVE-2026-40108?
CVE-2026-40108 allows for stored cross-site scripting (XSS) attacks that can affect users accessing ITIL costs.
4
Which versions of GLPI are affected by CVE-2026-40108?
CVE-2026-40108 affects GLPI versions from 11.0.0 through 11.0.6.
5
When was CVE-2026-40108 published?
CVE-2026-40108 was published on June 2, 2026.