OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-53625

HIGH · CVSS 7.5 EPSS 0.57% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

GLPI versions from 0.70 to 10.0.26 and 11.0.8 are vulnerable due to an API manipulation flaw that allows a technician to alter another user's authentication method, potentially enabling account takeover for super-administrators. Organizations using these versions, particularly those relying on the legacy API REST interface or SSO logins, should prioritize upgrading to the patched versions 11.0.8 or 10.0.26 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-53625
Severity
HIGH
CVSS
7.5
EPSS
0.57%

Original NVD Description

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another user's authentication method. Under configurations using the legacy API REST interface or SSO logins, this can change a super-administrator's authentication method and enable account takeover. This issue is fixed in versions 11.0.8 and 10.0.26.