CVE-2026-23624
EUVD-2026-536104.02.2026, 18:16
GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.0.5, when remote authentication is used, based on SSO variables, a user can steal a GLPI session previously opened by another user on the same machine. This issue has been patched in versions .Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| glpi-project | glpi | 0.71 ≤ 𝑥 < 10.0.23 |
| glpi-project | glpi | 11.0.0 ≤ 𝑥 < 11.0.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration