CVE-2026-23624mediumCWE-384

CVE-2026-23624: medium-severity vulnerability in glpi-project glpi

GLPI is vulnerable to session stealing on externally authenticated user change

Published

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.3epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.0.5, when remote authentication is used, based on SSO variables, a user can steal a GLPI session previously opened by another user on the same machine. This issue has been patched in versions .
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
glpi-project · glpi