CVE-2026-42317: GLPI vulnerable to arbitrary files deletion by technician
GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, a technician can delete arbitrary files from the filesystem as long as the webserver has write rights on them. Upgrade to 10.0.25 or 11.0.7 to receive a patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 10.0.25 - Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 11.0.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42317?
CVE-2026-42317 has a high severity rating of 7.
How do I fix CVE-2026-42317?
To fix CVE-2026-42317, upgrade GLPI to version 10.0.25 or 11.0.7.
What are the risks associated with CVE-2026-42317?
The risks include unauthorized deletion of arbitrary files by technicians who have write access to the filesystem.
Which GLPI versions are affected by CVE-2026-42317?
GLPI versions starting from 0.78 up to but not including 10.0.25 and 11.0.7 are affected by CVE-2026-42317.
Who is affected by CVE-2026-42317?
Technicians using vulnerable versions of GLPI can exploit CVE-2026-42317 to delete files from the filesystem.