CVE-2026-53625
Scheda descrittiva ricevuta da OpenCTI e minimizzata per la consultazione nel portale Intel.
- Condivisione
- PUBLIC-OSINT
- Confidenza
- 100
- Fonte
- The CVE Program
- Aggiornata
- 26/09/2026 05:22
Descrizione
GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another user's authentication method. Under configurations using the legacy API REST interface or SSO logins, this can change a super-administrator's authentication method and enable account takeover. This issue is fixed in versions 11.0.8 and 10.0.26.
Alias e classificazioni
Dettagli tecnici minimizzati
Nessun dato grezzo- cisa kev
- False
Riferimenti pubblici
- https://github.com/glpi-project/glpi/commit/eb1b4299e81abeac764902b422cf7fcd59ac85d0
https://github.com/glpi-project/glpi/commit/eb1b4299e81abeac764902b422cf7fcd59ac85d0 - https://github.com/glpi-project/glpi/releases/tag/11.0.8
https://github.com/glpi-project/glpi/releases/tag/11.0.8 - https://github.com/glpi-project/glpi/releases/tag/10.0.26
https://github.com/glpi-project/glpi/releases/tag/10.0.26 - https://github.com/glpi-project/glpi/commit/9329f1ecac8099b54c2ca4dd770d78f82e1e6db8
https://github.com/glpi-project/glpi/commit/9329f1ecac8099b54c2ca4dd770d78f82e1e6db8 - https://github.com/glpi-project/glpi/security/advisories/GHSA-94rp-v9f2-5rj7
https://github.com/glpi-project/glpi/security/advisories/GHSA-94rp-v9f2-5rj7
Catalogo Intel
La vulnerabilità è presente anche nel catalogo editoriale EudorIA.
Apri analisi EudorIALa presenza in OpenCTI descrive una correlazione di intelligence e non costituisce, da sola, prova di compromissione, attribuzione legale o indicazione operativa applicabile senza verifica del contesto.