CyberRota Analysis
AI-GeneratedGLPI versions from 0.70 to 10.0.26 and 11.0.8 are vulnerable due to an API manipulation flaw that allows a technician to alter another user's authentication method, potentially enabling account takeover for super-administrators. Organizations using these versions, particularly those relying on the legacy API REST interface or SSO logins, should prioritize upgrading to the patched versions 11.0.8 or 10.0.26 to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another user's authentication method. Under configurations using the legacy API REST interface or SSO logins, this can change a super-administrator's authentication method and enable account takeover. This issue is fixed in versions 11.0.8 and 10.0.26.