CVE-2026-49469

Source
https://cve.org/CVERecord?id=CVE-2026-49469
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49469.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-49469
Aliases
  • GHSA-3cgm-rj32-hfwf
Published
2026-09-25T18:25:43Z
Modified
2026-09-26T03:46:03Z
Severity
  • 4.6 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N CVSS Calculator
Summary
GLPI: LDAP filter injection in user import feature
Details

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP filter. This allows access to LDAP objects that the default filter was intended to exclude. This issue is fixed in versions 11.0.8 and 10.0.26.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-90"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49469.json"
}
References

Affected packages

Git / github.com/glpi-project/glpi

Affected ranges

Type
GIT
Repo
https://github.com/glpi-project/glpi
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0.70"
        },
        {
            "fixed":  "10.0.26"
        },
        {
            "introduced":  "11.0.0"
        },
        {
            "fixed":  "11.0.8"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

11.*
11.0.0
11.0.1
11.0.2
11.0.3
11.0.4
11.0.5
11.0.6
11.0.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49469.json"