CVE-2026-53627: GLPI: Unexpected access to update operations through the API
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to perform update operations that the same user is normally forbidden to perform through the user interface. The API update flow does not consistently enforce the applicable authorization checks. This issue is fixed in version 11.0.8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 11.0.8
Event History
Frequently Asked Questions
Who can exploit this issue?
A low-privileged authenticated GLPI user can exploit it. The issue is in the v2 API update flow, where authorization checks are not consistently enforced.
Which installations are affected?
GLPI versions from 11.0.0 through 11.0.8 are identified as affected. The issue is fixed in version 11.0.8.
What access does an attacker need?
The attacker needs an authenticated GLPI account, even if that account has low privileges. The provided information does not indicate that unauthenticated exploitation is possible.