CVE-2026-22248Disclosure(teclib-edition / glpi)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. From 11.0.0 to before 11.0.5, an authenticated technician user can upload a malicious file and trigger its execution through an unsafe PHP instantiation. This vulnerability is fixed in 11.0.5.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • glpi

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-15)
  • 3 total mentions across 2 days

Affected systems

Products
glpi

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-11: 1Mentions · 2026-03-15: 2Technical Details · 2026-03-11: 103-1103-15
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-111
Disclosure1
2026-03-152
Disclosure1General1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-22248 GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. From 11.0.0 to befo… https://www.cve.org/CVERecord?id=CVE-2026-22248 ----- Traducción: CVE-2026-22248 GLP… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-22248 affecting GLPI and links to the CVE record, but offers no deeper technical, exploit, or patch information.

    0000042
    57 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-22248 GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. From 11.0.0 to befo… https://www.cve.org/CVERecord?id=CVE-2026-22248

    Post summary

    The post merely lists CVE‑2026‑22248 for GLPI, offering no technical, exploit, or mitigation details.

    00000229
    56.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-22248 - High GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. From 11.0.0 to before 11.0.5, an authenticat... https://www.thehackerwire.com/vulnerability/CVE-2026-22248/ https://t.co/lq5E6xt0Fh

    Post summary

    The tweet announces a high‑severity CVE (CVE‑2026‑22248) that affects GLPI versions 11.0.0‑11.0.4 by enabling an authentication bypass; no exploitation or patch details are included.

    0000037
    134 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appteclib-editionglpi---

Explore more