CVE-2026-53629: GLPI: SQL injection in history tab
GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL for the history tab that injects attacker-controlled values into a database query. This permits SQL injection through the history tab endpoint. This issue is fixed in versions 11.0.8 and 10.0.26.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 11.0.8 - Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 10.0.26
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must have a GLPI account with the READ right on logs. The issue is exposed through the history tab endpoint, where the attacker can craft a malicious URL.
Which GLPI versions need remediation?
The affected range starts at GLPI 9.4.0 and extends through versions before 10.0.26 and 11.0.8. Upgrade to 10.0.26 or 11.0.8, as applicable.
What capability does successful exploitation provide?
Successful exploitation permits SQL injection by placing attacker-controlled values into a database query through the history tab.