GLPI Arbitrary File Read Vulnerability

Vulnerability

A vulnerability allowing arbitrary file read has been identified in GLPI versions 0.50 prior to 10.0.25 and 11.0.0 prior to 11.0.7. This issue allows technicians to access any file within the GLPI_DOC_DIR.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files within the GLPI_DOC_DIR, potentially exposing confidential information.

Remediation

Users are advised to upgrade to GLPI versions 10.0.25 or 11.0.7.

Added: Jun 3, 2026, 4:23 PM
Updated: Jun 3, 2026, 4:23 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
9.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.