CVE-2026-53625: GLPI: Privilege Escalation via authtype API manipulation
GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another user's authentication method. Under configurations using the legacy API REST interface or SSO logins, this can change a super-administrator's authentication method and enable account takeover. This issue is fixed in versions 11.0.8 and 10.0.26.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPI 10.xto a version that resolves this vulnerability.Fixed in 10.0.26 - Upgrade
Upgrade
GLPI 11.xto a version that resolves this vulnerability.Fixed in 11.0.8
Event History
Frequently Asked Questions
Which deployments are at greatest risk of account takeover?
Deployments that use the legacy REST API interface or SSO logins are specifically identified as at risk. In those configurations, a technician may be able to alter a super-administrator's authentication method and take over the account.
What level of access does an attacker need?
The attacker must already have technician-level access and be able to manipulate the authtype value through the API. The issue is an authenticated privilege-escalation flaw rather than an unauthenticated attack.
Are current releases affected?
The issue is fixed in GLPI 10.0.26 and 11.0.8. Versions from 0.70 through versions preceding those fixes are affected.