๐Ÿ” CVE Alert

CVE-2026-49469

UNKNOWN 0.0

GLPI: LDAP filter injection in user import feature

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP filter. This allows access to LDAP objects that the default filter was intended to exclude. This issue is fixed in versions 11.0.8 and 10.0.26.

CWE CWE-90
Vendor glpi-project
Product glpi
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for glpi-project glpi

Be the first to know when new unknown vulnerabilities affecting glpi-project glpi are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

glpi-project / glpi
>= 0.70, < 10.0.26 >= 11.0.0, < 11.0.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/glpi-project/glpi/security/advisories/GHSA-3cgm-rj32-hfwf github.com: https://github.com/glpi-project/glpi/commit/4fb3056bcd292b515acce96887f1376ce6d5aba8 github.com: https://github.com/glpi-project/glpi/commit/d413b48ea97b2f73ba30c90ae0d029aac860f71a github.com: https://github.com/glpi-project/glpi/releases/tag/10.0.26 github.com: https://github.com/glpi-project/glpi/releases/tag/11.0.8