CVE-2026-23489

CRITICAL

Fields GLPI plugin vulnerable to RCE in dropdown generation

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-23489. PoCs published by eorll-lgtm.

AI-analyzed exploit summary This exploit demonstrates authenticated remote code execution (RCE) in the GLPI 'Fields' plugin <=1.23.2 by injecting PHP code into a custom dropdown field label, which is then executed when the plugin generates a PHP class. The exploit is blind and requires a super-admin session cookie.

Description

Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdowns. This issue has been patched in version 1.23.3.

Exploits (1)

github WORKING POC
by eorll-lgtm · pythonpoc
https://github.com/eorll-lgtm/poc-CVE-2026-23489

This exploit demonstrates authenticated remote code execution (RCE) in the GLPI 'Fields' plugin <=1.23.2 by injecting PHP code into a custom dropdown field label, which is then executed when the plugin generates a PHP class. The exploit is blind and requires a super-admin session cookie.

Classification
Working Poc 99%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: GLPI Fields plugin <=1.23.2
Auth required
Prerequisites: Super-admin access to GLPI with a valid session cookie · GLPI 'Fields' plugin installed and active (<=1.23.2) · Ability to send HTTP requests to the target instance
mistral-large-3 · analyzed Aug 05, 2026 Full analysis →

References (2)

Core 2
Core References

Scores

CVSS v3 9.1
EPSS 0.0030
EPSS Percentile 22.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (2)
pluginsGLPI/fields < 1.23.3
teclib-edition/fields < 1.23.3
Published Mar 16, 2026
Tracked Since Mar 16, 2026