CVE-2026-32312

MEDIUM

GLPI: Unauthorized export of form structure

Title source: cna
STIX 2.1

Description

GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthorized forms. This issue has been fixed in version 11.0.7.

References (2)

Core 2
Core References

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 10.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
glpi-project/glpi 11.0.0 - 11.0.7
glpi-project/glpi >= 11.0.0, < 11.0.7
Published May 19, 2026
Tracked Since May 19, 2026