CVE-2026-13490Disclosure

LOWCVSS 6.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document::canViewFile of the file front/document.send.php of the component Document Handler. Such manipulation of the argument docid leads to authorization bypass. The attack can be executed remotely. This attack is characterized by high complexity. It is indicated that the exploitability is difficult. The vendor was contacted early about this disclosure.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-28: 3Technical Details · 2026-06-28: 306-28
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13490 A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document::canViewFile of the file front/document.send.… https://www.cve.org/CVERecord?id=CVE-2026-13490 ----- Traducción: CVE-2026-13490 Se … http://infoflow.cloud`

    Post summary

    The snippet discloses CVE-2026-13490, detailing affected GLPI versions and the vulnerable function, without any PoC, exploit, or patch information.

    0001035
    89 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-13490 A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document::canViewFile of the file front/document.send.… https://www.cve.org/CVERecord?id=CVE-2026-13490

    Post summary

    CVE-2026-13490 is noted to affect the Document::canViewFile function in glpi, but no PoC, exploit, patch, or evidence of active exploitation is provided.

    000101.3K
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-13490 Authorization Bypass in GLPI Document Handler via docid Parameter... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13490 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    An alert has been released on CVE‑2026‑13490, describing an authorization bypass in GLPI’s Document Handler through the docid parameter, but it contains no PoC, exploit code, patch information, or evidence of active exploitation.

    00010141
    4.1K followersView on X

Explore more