CVE-2026-42321: GLPI has stored XSS in asset locks
GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a technician can store an XSS payload in the asset locked tab. Upgrade to 10.0.25 or 11.0.7 to receive a patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 10.0.25 - Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 11.0.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42321?
The severity of CVE-2026-42321 is high, with a CVSS score of 8.4.
How do I fix CVE-2026-42321?
To fix CVE-2026-42321, upgrade your GLPI software to version 10.0.25 or 11.0.7.
What type of vulnerability is CVE-2026-42321?
CVE-2026-42321 is a stored cross-site scripting (XSS) vulnerability.
Which versions of GLPI are affected by CVE-2026-42321?
CVE-2026-42321 affects GLPI versions starting from 10.0.4 and prior to 10.0.25.
Can CVE-2026-42321 be exploited remotely?
Yes, CVE-2026-42321 can be exploited remotely due to its nature as a stored XSS vulnerability.