CVE-2026-53625: GLPI: Privilege Escalation via authtype API manipulation

Published Sep 25, 2026
·
Updated

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another user's authentication method. Under configurations using the legacy API REST interface or SSO logins, this can change a super-administrator's authentication method and enable account takeover. This issue is fixed in versions 11.0.8 and 10.0.26.

Affected Software

1 affected component
GLPI GLPI>=0.70<10.0.26, >=11.0<11.0.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade GLPI 10.x to a version that resolves this vulnerability.

    Fixed in 10.0.26
  2. Upgrade

    Upgrade GLPI 11.x to a version that resolves this vulnerability.

    Fixed in 11.0.8

Event History

Sep 25, 2026
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are at greatest risk of account takeover?

Deployments that use the legacy REST API interface or SSO logins are specifically identified as at risk. In those configurations, a technician may be able to alter a super-administrator's authentication method and take over the account.

2

What level of access does an attacker need?

The attacker must already have technician-level access and be able to manipulate the authtype value through the API. The issue is an authenticated privilege-escalation flaw rather than an unauthenticated attack.

3

Are current releases affected?

The issue is fixed in GLPI 10.0.26 and 11.0.8. Versions from 0.70 through versions preceding those fixes are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203