GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthorized forms. This issue has been fixed in version 11.0.7.
References
| Link | Resource |
|---|---|
| https://github.com/glpi-project/glpi/releases/tag/11.0.7 | Release Notes |
| https://github.com/glpi-project/glpi/security/advisories/GHSA-cg63-qchq-q626 | Vendor Advisory |
Configurations
History
21 May 2026, 23:57
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/glpi-project/glpi/releases/tag/11.0.7 - Release Notes | |
| References | () https://github.com/glpi-project/glpi/security/advisories/GHSA-cg63-qchq-q626 - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
| CPE | cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:* | |
| First Time |
Glpi-project glpi
Glpi-project |
19 May 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-19 00:16
Updated : 2026-05-21 23:57
NVD link : CVE-2026-32312
Mitre link : CVE-2026-32312
CVE.ORG link : CVE-2026-32312
JSON object : View
Products Affected
glpi-project
- glpi
CWE
CWE-862
Missing Authorization
