CVE-2026-42320: GLPI vulnerable to arbitrary file access
GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0.7, a technician can read arbitrary files inside the GLPIDOCDIR. Upgrade to 10.0.25 or 11.0.7 to receive a patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 10.0.25 - Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 11.0.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42320?
The severity of CVE-2026-42320 is medium with a CVSS score of 5.9.
How do I fix CVE-2026-42320?
To address CVE-2026-42320, upgrade your GLPI software to version 10.0.25 or 11.0.7.
What does CVE-2026-42320 affect?
CVE-2026-42320 affects versions of GLPI from 0.50 up to but not including 10.0.25 and 11.0.7.
What is the impact of CVE-2026-42320?
The impact of CVE-2026-42320 is that unauthorized users can access arbitrary files within the GLPI_DOC_DIR.
Is CVE-2026-42320 a critical vulnerability?
CVE-2026-42320 is not classified as critical; it has a medium severity rating.