CRITICAL
GLPI: RCE via Form import
Published Sep 25, 2026
9.4
CRITICALCVSS 4.0
EPSS 0.34%
Description
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset directory. The imported file can be written to an executable server location, allowing a malicious script to be invoked remotely. This issue is fixed in version 11.0.8.
Affected products
-
- Version >= 11.0.0, < 11.0.8StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Glpi-Project | Glpi | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://github.com/glpi-project/glpi/commit/d817cb5c17e3368c89d4a561a43a777662b9da19 x_refsource_MISC
- https://github.com/glpi-project/glpi/releases/tag/11.0.8 x_refsource_MISC
- https://github.com/glpi-project/glpi/security/advisories/GHSA-6whc-g4h2-98rm x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://github.com/glpi-project/glpi/commit/d817cb5c17e3368c89d4a561a43a777662b9da19 | x_refsource_MISC | |
| https://github.com/glpi-project/glpi/releases/tag/11.0.8 | x_refsource_MISC | |
| https://github.com/glpi-project/glpi/security/advisories/GHSA-6whc-g4h2-98rm | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 25, 2026
Updated Sep 25, 2026
Reserved May 21, 2026
Link CVE-2026-48482
CISA Vulnrichment
Updated Sep 30, 2026