Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-48482: GLPI enables remote code execution via malicious form import
CVE-2026-48482 · published 2 days ago
Summary
Versions 11.0.0 through 11.0.7 of the GLPI IT management tool let a user with form‑admin rights upload a specially crafted image that is saved outside the intended folder. This can place executable code on the server that an attacker can run remotely. Upgrade to version 11.0.8 or later to stop this behavior.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| glpi-project | glpi | >= 11.0.0, < 11.0.8 |
Original advisory text
GLPI: RCE via Form import
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset directory. The imported file can be written to an executable server location, allowing a malicious script to be invoked remotely. This issue is fixed in version 11.0.8.
References
- https://github.com/glpi-project/glpi/commit/d817cb5c17e3368c89d4a561a43a777662b9... x_refsource_MISC
- https://github.com/glpi-project/glpi/releases/tag/11.0.8 x_refsource_MISC
- https://github.com/glpi-project/glpi/security/advisories/GHSA-6whc-g4h2-98rm x_refsource_CONFIRM
Severity
9.4
Critical
CVSS 4.0: 9.4 (NVD)
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
Timeline
Published25 Sep 2026
Updated27 Sep 2026
First seen25 Sep 2026
Track software like this
Free during beta