CVE-2026-23624: medium-severity vulnerability in glpi-project glpi
GLPI is vulnerable to session stealing on externally authenticated user change
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.3epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.0.5, when remote authentication is used, based on SSO variables, a user can steal a GLPI session previously opened by another user on the same machine. This issue has been patched in versions .
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
glpi-project · glpiRelated CVEs — glpi-project glpi
In the same product, most dangerous first.
CVE-2025-24799HIGHGLPI allows unauthenticated SQL injection through the inventory endpointEPSS 86.7%CVE-2020-15175HIGHUnauthenticated File Deletion in GLPIEPSS 71.5%CVE-2023-46727HIGHGLPI SQL injection through inventory agent requestEPSS 67.7%CVE-2024-29889HIGHGLPI contains an SQL injection through the saved searchesEPSS 63.0%CVE-2024-31456HIGHGLPI contains an authenticated SQL injectionEPSS 59.1%CVE-2024-27096HIGHSQL Injection in through the search engineEPSS 58.8%