GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthorized forms. This issue has been fixed in version 11.0.7.
History

Tue, 19 May 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 19 May 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Glpi-project
Glpi-project glpi
Vendors & Products Glpi-project
Glpi-project glpi

Tue, 19 May 2026 00:15:00 +0000

Type Values Removed Values Added
Description GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthorized forms. This issue has been fixed in version 11.0.7.
Title GLPI: Unauthorized export of form structure
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-05-18T23:46:26.200Z

Updated: 2026-05-19T12:10:53.021Z

Reserved: 2026-03-11T21:16:21.660Z

Link: CVE-2026-32312

cve-icon Vulnrichment

Updated: 2026-05-19T12:10:48.325Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-19T00:16:37.283

Modified: 2026-05-19T15:03:31.370

Link: CVE-2026-32312

cve-icon Redhat

No data.