GLPI Session Stealing Vulnerability in Externally Authenticated Users

Vulnerability

A session stealing vulnerability has been identified in GLPI (Gestionnaire Libre de Parc Informatique) versions 0.71 and 0.71 prior to 10.0.23 and 11.0.5. When remote authentication is utilized, based on Single Sign-On (SSO) variables, a user can hijack a GLPI session that was previously opened by another user on the same machine.

Impact

Exploitation of this vulnerability allows for session hijacking, where an attacker can take over another user's session.

Remediation

Users are advised to upgrade to GLPI versions 10.0.23 or 11.0.5.

Added: Feb 4, 2026, 6:55 PM
Updated: Feb 4, 2026, 6:55 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
5.0
exploitability
5.0
remediation
7.7
relevance
2.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.