OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-49470

HIGH · CVSS 7.7 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects GLPI versions 11.0.0 to 11.0.8, where the time-based one-time password (TOTP) verification endpoint lacks restrictions on failed submission attempts per user. This flaw allows attackers with a user's primary credentials to perform brute-force attacks on the multi-factor authentication (MFA) process, potentially leading to account takeover. Organizations using affected versions of GLPI should prioritize upgrading to version 11.0.8 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-49470
Severity
HIGH
CVSS
7.7
EPSS
0.36%

Original NVD Description

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not limit failed submissions per user. An attacker who has obtained a user's primary authentication credentials can repeatedly submit TOTP values against the MFA verification flow, making brute-force compromise of the second factor and subsequent account takeover possible. This issue is fixed in version 11.0.8.