CVE-2026-23624

GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.0.5, when remote authentication is used, based on SSO variables, a user can steal a GLPI session previously opened by another user on the same machine. This issue has been patched in versions .
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:21

Type Values Removed Values Added
Summary
  • (es) GLPI es un paquete de software gratuito de gestión de activos y TI. En versiones desde la 0.71 hasta antes de la 10.0.23 y antes de la 11.0.5, cuando se utiliza la autenticación remota, basada en variables SSO, un usuario puede robar una sesión GLPI previamente abierta por otro usuario en la misma máquina. Este problema ha sido parcheado en las versiones .

06 Feb 2026, 21:18

Type Values Removed Values Added
References () https://github.com/glpi-project/glpi/releases/tag/10.0.23 - () https://github.com/glpi-project/glpi/releases/tag/10.0.23 - Product, Release Notes
References () https://github.com/glpi-project/glpi/releases/tag/11.0.5 - () https://github.com/glpi-project/glpi/releases/tag/11.0.5 - Product, Release Notes
References () https://github.com/glpi-project/glpi/security/advisories/GHSA-5j4j-vx46-r477 - () https://github.com/glpi-project/glpi/security/advisories/GHSA-5j4j-vx46-r477 - Vendor Advisory
CPE cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*
First Time Glpi-project
Glpi-project glpi

04 Feb 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-04 18:16

Updated : 2026-06-17 10:21


NVD link : CVE-2026-23624

Mitre link : CVE-2026-23624

CVE.ORG link : CVE-2026-23624


JSON object : View

Products Affected

glpi-project

  • glpi
CWE
CWE-384

Session Fixation