Rıdvan Yağlı[verified]@ridvanyagliPoC
A proof‑of‑concept for CVE‑2026‑23489, a critical RCE in the GLPI Fields Plugin (≤1.23.2), has been released and linked publicly, but there is no evidence of active exploitation or an accompanying patch.
The Hacker Wire@TheHackerWireDisclosure
The post announces CVE-2026-23489, noting that a GLPI plugin version prior to 1.23.3 permits arbitrary PHP code execution. No PoC, exploit code, or patch information is provided.
CVEFind.com@CveFindComPatch
The GLPI Fields plugin before version 1.23.3 permits arbitrary PHP code execution when users create dropdowns; applying the patch resolves this critical issue.
0day Signal@0dayPublishingDisclosure
This post announces the discovery of a PHP code injection vulnerability (CVE-2026-23489) in the GLPI Fields plugin that could allow privileged users to drop shells via a form field, but no PoC, exploit code, patch, or active exploitation is reported.
cybrmonk@cybr_monkExploit
The text announces that public exploit code is now available for CVE-2026-23489, a Remote Code Execution vulnerability in the GLPI Fields Plugin, pointing to a blog post with further details.
CVE@CVEnewDisclosure
CVE-2026-23489 discloses that the GLPI Fields plugin (pre‑v1.23.3) permits arbitrary PHP code execution via custom fields, but no PoC, exploit code, active attacks, or patch information are provided.