CVE-2026-55217: GLPI: Unallowed modfication of knowbase items comments and translations
GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete knowledge base comments and translations without the required authorization for the affected content. This issue is fixed in versions 11.0.8 and 10.0.26.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 10.0.26
Event History
Frequently Asked Questions
Who can exploit this issue?
A low-privileged authenticated GLPI user can exploit it. The issue allows that user to create, update, or delete knowledge base comments and translations without the authorization normally required for the affected content.
Which GLPI versions are affected and which versions contain the fix?
Affected versions range from 0.85 through versions before 10.0.26 and 11.0.8. The issue is fixed in GLPI 10.0.26 and 11.0.8.