<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>GLPI 11.0.x &lt; 11.0.8 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/glpi-11.0.x--11.0.8/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 22 Jul 2026 14:51:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/glpi-11.0.x--11.0.8/feed.xml" rel="self" type="application/rss+xml"/><item><title>Multiple Vulnerabilities in GLPI</title><link>https://feed.craftedsignal.io/briefs/2026-07-glpi-vulnerabilities/</link><pubDate>Wed, 22 Jul 2026 14:51:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-glpi-vulnerabilities/</guid><description>Multiple vulnerabilities have been discovered in GLPI, specifically affecting versions 11.0.x prior to 11.0.8 and all versions prior to 10.0.26, which allow an attacker to compromise data confidentiality and integrity, and bypass security policies.</description><content:encoded><![CDATA[<p>CERT-FR has issued an advisory regarding multiple vulnerabilities identified in GLPI, an open-source IT asset management software. These vulnerabilities, tracked as CVE-2026-45801, CVE-2026-53627, CVE-2026-53628, and CVE-2026-55217, were disclosed on July 22, 2026, following bulletins from GLPI-Project. The affected versions include GLPI 11.0.x prior to 11.0.8 and all GLPI versions prior to 10.0.26. Successful exploitation of these flaws could lead to severe consequences, including unauthorized access to sensitive information (data confidentiality compromise), unauthorized modification or corruption of data (data integrity compromise), and the circumvention of existing security policies within the GLPI application. Organizations using vulnerable GLPI instances are at risk of significant data breaches and operational disruption.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An attacker identifies an internet-facing or internal GLPI instance running a vulnerable version (11.0.x prior to 11.0.8 or prior to 10.0.26).</li>
<li>The attacker performs reconnaissance to understand the specific GLPI deployment and potential entry points.</li>
<li>Leveraging publicly available information or reverse-engineering, the attacker crafts malicious HTTP requests tailored to exploit one or more of the identified vulnerabilities (CVE-2026-45801, CVE-2026-53627, CVE-2026-53628, CVE-2026-55217).</li>
<li>These specially crafted requests are sent to the vulnerable GLPI web server, attempting to trigger the underlying flaw.</li>
<li>Successful exploitation leads to the circumvention of GLPI's internal security policies and access controls, granting the attacker unauthorized privileges or access to restricted functionalities.</li>
<li>The attacker then leverages this unauthorized access to view sensitive data stored within the GLPI application, compromising data confidentiality.</li>
<li>Alternatively, or in conjunction, the attacker may modify or corrupt existing data records within GLPI, leading to a compromise of data integrity.</li>
<li>The attacker verifies the success of the data compromise (confidentiality or integrity) and the policy circumvention.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The successful exploitation of these vulnerabilities can lead to significant impact on organizations utilizing GLPI. Attackers can gain unauthorized access to sensitive IT asset information, user details, and operational data, leading to a breach of data confidentiality. Furthermore, the ability to modify data could result in corrupted inventory records, altered service requests, or manipulated user credentials, severely impacting data integrity and potentially disrupting IT operations. The circumvention of security policies means that existing protective measures within GLPI could be bypassed, leaving the system vulnerable to further unauthorized actions and potentially wider network access depending on the GLPI deployment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately apply the security patches provided by GLPI-Project to upgrade affected GLPI instances to version 11.0.8 or later for the 11.0.x branch, or 10.0.26 or later for the 10.0.x branch, as detailed in the referenced GLPI security bulletins.</li>
<li>Monitor web server access logs for unusual request patterns, especially those targeting GLPI URLs, that might indicate exploitation attempts for CVE-2026-45801, CVE-2026-53627, CVE-2026-53628, and CVE-2026-55217.</li>
<li>Review GLPI audit logs for unauthorized data access, modification events, or unexpected changes in user permissions that could signal a security policy bypass or data integrity compromise.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>vulnerability</category><category>web-application</category><category>glpi</category><category>data-breach</category><category>data-integrity</category><category>security-policy-bypass</category></item></channel></rss>