{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/glpi-project/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GLPI \u003c 10.0.26","GLPI 11.0.x \u003c 11.0.8"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","web-application","glpi","data-breach","data-integrity","security-policy-bypass"],"_cs_type":"advisory","_cs_vendors":["GLPI-Project"],"content_html":"\u003cp\u003eCERT-FR has issued an advisory regarding multiple vulnerabilities identified in GLPI, an open-source IT asset management software. These vulnerabilities, tracked as CVE-2026-45801, CVE-2026-53627, CVE-2026-53628, and CVE-2026-55217, were disclosed on July 22, 2026, following bulletins from GLPI-Project. The affected versions include GLPI 11.0.x prior to 11.0.8 and all GLPI versions prior to 10.0.26. Successful exploitation of these flaws could lead to severe consequences, including unauthorized access to sensitive information (data confidentiality compromise), unauthorized modification or corruption of data (data integrity compromise), and the circumvention of existing security policies within the GLPI application. Organizations using vulnerable GLPI instances are at risk of significant data breaches and operational disruption.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies an internet-facing or internal GLPI instance running a vulnerable version (11.0.x prior to 11.0.8 or prior to 10.0.26).\u003c/li\u003e\n\u003cli\u003eThe attacker performs reconnaissance to understand the specific GLPI deployment and potential entry points.\u003c/li\u003e\n\u003cli\u003eLeveraging publicly available information or reverse-engineering, the attacker crafts malicious HTTP requests tailored to exploit one or more of the identified vulnerabilities (CVE-2026-45801, CVE-2026-53627, CVE-2026-53628, CVE-2026-55217).\u003c/li\u003e\n\u003cli\u003eThese specially crafted requests are sent to the vulnerable GLPI web server, attempting to trigger the underlying flaw.\u003c/li\u003e\n\u003cli\u003eSuccessful exploitation leads to the circumvention of GLPI's internal security policies and access controls, granting the attacker unauthorized privileges or access to restricted functionalities.\u003c/li\u003e\n\u003cli\u003eThe attacker then leverages this unauthorized access to view sensitive data stored within the GLPI application, compromising data confidentiality.\u003c/li\u003e\n\u003cli\u003eAlternatively, or in conjunction, the attacker may modify or corrupt existing data records within GLPI, leading to a compromise of data integrity.\u003c/li\u003e\n\u003cli\u003eThe attacker verifies the success of the data compromise (confidentiality or integrity) and the policy circumvention.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of these vulnerabilities can lead to significant impact on organizations utilizing GLPI. Attackers can gain unauthorized access to sensitive IT asset information, user details, and operational data, leading to a breach of data confidentiality. Furthermore, the ability to modify data could result in corrupted inventory records, altered service requests, or manipulated user credentials, severely impacting data integrity and potentially disrupting IT operations. The circumvention of security policies means that existing protective measures within GLPI could be bypassed, leaving the system vulnerable to further unauthorized actions and potentially wider network access depending on the GLPI deployment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately apply the security patches provided by GLPI-Project to upgrade affected GLPI instances to version 11.0.8 or later for the 11.0.x branch, or 10.0.26 or later for the 10.0.x branch, as detailed in the referenced GLPI security bulletins.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for unusual request patterns, especially those targeting GLPI URLs, that might indicate exploitation attempts for CVE-2026-45801, CVE-2026-53627, CVE-2026-53628, and CVE-2026-55217.\u003c/li\u003e\n\u003cli\u003eReview GLPI audit logs for unauthorized data access, modification events, or unexpected changes in user permissions that could signal a security policy bypass or data integrity compromise.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T14:51:24Z","date_published":"2026-07-22T14:51:24Z","id":"https://feed.craftedsignal.io/briefs/2026-07-glpi-vulnerabilities/","summary":"Multiple vulnerabilities have been discovered in GLPI, specifically affecting versions 11.0.x prior to 11.0.8 and all versions prior to 10.0.26, which allow an attacker to compromise data confidentiality and integrity, and bypass security policies.","title":"Multiple Vulnerabilities in GLPI","url":"https://feed.craftedsignal.io/briefs/2026-07-glpi-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - GLPI-Project","version":"https://jsonfeed.org/version/1.1"}