5.3
CVE-2026-55217
- EPSS 0.31%
- Veröffentlicht 25.09.2026 18:29:28
- Zuletzt bearbeitet 25.09.2026 19:17:38
- Erkennungen
GLPI: Unallowed modfication of knowbase items comments and translations
GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete knowledge base comments and translations without the required authorization for the affected content. This issue is fixed in versions 11.0.8 and 10.0.26.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerglpi-project
≫
Produkt
glpi
Version
>= 0.85, < 10.0.26
Status
affected
Version
>= 11.0.0, < 11.0.8
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.217 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-285 Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/glpi-project/glpi/releases/tag/10.0.26
https://github.com/glpi-project/glpi/releases/tag/11.0.8
https://github.com/glpi-project/glpi/security/advisories/GHSA-xm3v-3g6q-g9q8
https://github.com/glpi-project/glpi/commit/1cbf69b99dfd0610f1c03a3f245f3b248e1bfde0
https://github.com/glpi-project/glpi/commit/9c29f25bd09eca9e62ca50c52b3ebd15b02997b2