CPE
CVE-2026-23489 is a blind remote code execution vulnerability in the GLPI Fields plugin (<= 1.23.2) that allows authenticated attackers to execute arbitrary PHP code via the dropdown-generation feature.