Vulnerability Description
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with access to planning can delete any object in GLPI. Upgrade to 11.0.7 or 10.0.25 to receive a patch. As a workaround, disable delete rights for User's planning.
Related Weaknesses (CWE)
References
- https://github.com/glpi-project/glpi/security/advisories/GHSA-w7mr-3vwm-2j22
- https://vokecyber.com/research/cve-2026-42318-glpi-arbitrary-deletion
FAQ
What is CVE-2026-42318?
CVE-2026-42318 is a documented vulnerability. GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with access to planning can delete any object in GLPI. ...
How severe is CVE-2026-42318?
CVSS scoring is not yet available for CVE-2026-42318. Check NVD for updates.
Is there a patch for CVE-2026-42318?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.