GLPI Unauthorized Asset Object Reading Vulnerability

Vulnerability

A vulnerability exists in GLPI versions 11.0.0 prior to 11.0.7 and in versions 0.78 prior to 10.0.25. An authenticated user with 'config READ' permission can unauthorizedly read a specific asset object.

Impact

This vulnerability allows for unauthorized reading of asset objects by users with 'config READ' permission.

Remediation

Users are advised to upgrade to GLPI version 11.0.7 or 10.0.25.

Added: Jun 3, 2026, 4:20 PM
Updated: Jun 3, 2026, 4:20 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.6
exploitability
5.2
remediation
7.7
relevance
9.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.