CVE-2026-42318: GLPI Vulnerable to Arbitrary Item Deletion via Planning Endpoint
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with access to planning can delete any object in GLPI. Upgrade to 11.0.7 or 10.0.25 to receive a patch. As a workaround, disable delete rights for User's planning.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.0.7 - Configuration
As a workaround, disable delete rights for users with planning access so low-privilege users cannot delete arbitrary objects via the planning endpoint.
GLPI planning endpoint / user permissions delete rights for User's planning = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42318?
The severity of CVE-2026-42318 is high, rated at 7 on the CVSS scale.
How do I fix CVE-2026-42318?
To fix CVE-2026-42318, upgrade GLPI to versions 10.0.25 or 11.0.7.
Who is affected by CVE-2026-42318?
Users with low privileges who have access to the planning feature of GLPI are affected by CVE-2026-42318.
What can happen if CVE-2026-42318 is exploited?
If exploited, CVE-2026-42318 allows low privilege users to delete arbitrary objects in GLPI.
Is there a workaround for CVE-2026-42318?
Yes, as a workaround for CVE-2026-42318, you can disable delete rights for users in the planning feature.