← Back to browse · API

CVE-2026-26026

Severity
CRITICAL
CVSS
9.1
EPSS
0.11312
Risk score
40.36
CISA KEV
No
PoC
No
Published
2026-04-06
Modified
2026-04-07
First seen
2026-08-07
Aliases
EUVD-2026-19246
Products
glpi-project:glpi 11.0.0, < 11.0.6
Sources
euvd EUVD-2026-19246

Description

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6.

References