LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-26001

glpi-project · glpi inventory

Published
CVSS7.1
Severityhigh
WeaknessCWE-89
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Description

The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, non sanitized user input can lend to an SQL injection from reports, with adequate rights. This vulnerability is fixed in 1.6.6.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-26001

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-26001.