CVE-2026-49470: GLPI: Missing Rate Limiting on Login and TOTP Verification — Account Takeover via Brute Force
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not limit failed submissions per user. An attacker who has obtained a user's primary authentication credentials can repeatedly submit TOTP values against the MFA verification flow, making brute-force compromise of the second factor and subsequent account takeover possible. This issue is fixed in version 11.0.8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 11.0.8
Event History
Frequently Asked Questions
Which deployments are affected?
GLPI versions from 11.0.0 through 11.0.8 are identified as affected. The issue concerns the TOTP verification endpoint used in the MFA flow.
What does an attacker need before exploiting this issue?
An attacker must already have obtained a user's primary authentication credentials. They can then repeatedly submit TOTP values during MFA verification to brute-force the second factor.
How can this be remediated?
Upgrade GLPI to version 11.0.8, which fixes the issue.