Home

Description

GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.0.5, when remote authentication is used, based on SSO variables, a user can steal a GLPI session previously opened by another user on the same machine. This issue has been patched in versions .

PUBLISHED Reserved 2026-01-14 | Published 2026-02-04 | Updated 2026-02-04 | Assigner GitHub_M




MEDIUM: 4.3CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-384: Session Fixation

Product status

>= 0.71, < 10.0.23
affected

>= 11.0.0-alpha, < 11.0.5
affected

References

github.com/...t/glpi/security/advisories/GHSA-5j4j-vx46-r477

github.com/glpi-project/glpi/releases/tag/10.0.23

github.com/glpi-project/glpi/releases/tag/11.0.5

cve.org (CVE-2026-23624)

nvd.nist.gov (CVE-2026-23624)

Download JSON