CVE-2026-23489Disclosure(teclib-edition / fields)

MEDIUMCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch teclib-edition fields systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdowns. This issue has been patched in version 1.23.3.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fields

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-16); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
fields

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-16: 3Mentions · 2026-03-17: 1Mentions · 2026-09-13: 1Mentions · 2026-09-14: 1PoC Mentioned / Linked · 2026-09-13: 1PoC Mentioned / Linked · 2026-09-14: 1Exploit Tool / Code · 2026-09-13: 1Exploit Tool / Code · 2026-09-14: 1Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-16: 3Technical Details · 2026-03-17: 1Technical Details · 2026-09-13: 1Technical Details · 2026-09-14: 103-1603-1709-1309-14
Signal classification4 categories
Disclosure
350.0%
Patch
116.7%
Exploit
116.7%
PoC
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-163
Disclosure2Patch1
2026-03-171
Disclosure1
2026-09-131
Exploit1
2026-09-141
PoC1
Full discourse6 posts
  • Rıdvan Yağlı@ridvanyagli
    PoC

    GLPI Fields Plugin'deki CVE-2026-23489 CVSS 9.1 Critical RCE açığını hedefleyen PoC yayınlandı. Fields Plugin ≤1.23.2 etkileniyor. https://github.com/eorll-lgtm/poc-CVE-2026-23489

    Post summary

    A proof‑of‑concept for CVE‑2026‑23489, a critical RCE in the GLPI Fields Plugin (≤1.23.2), has been released and linked publicly, but there is no evidence of active exploitation or an accompanying patch.

    03023111.3K
    2.4K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-23489 - Critical Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to cr... https://www.thehackerwire.com/vulnerability/CVE-2026-23489/ https://t.co/j1vSKZh2AG

    Post summary

    The post announces CVE-2026-23489, noting that a GLPI plugin version prior to 1.23.3 permits arbitrary PHP code execution. No PoC, exploit code, or patch information is provided.

    0001167
    136 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-23489: CRITICAL] GLPI Fields plugin pre-1.23.3 allows execution of arbitrary PHP code by users creating dropdowns, impacting cybersecurity. Update to patch this critical vulnerability.#cve,CVE-2026-23489,#cybersecurity https://cvefind.com/CVE-2026-23489

    Post summary

    The GLPI Fields plugin before version 1.23.3 permits arbitrary PHP code execution when users create dropdowns; applying the patch resolves this critical issue.

    00010146
    601 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-23489: Fields GLPI plugin vulnerable to... PHP code injection through dropdown creation in GLPI Fields plugin - privileged users can drop shells via form field ma... https://zerodaysignal.com/vulnerability/CVE-2026-23489 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    This post announces the discovery of a PHP code injection vulnerability (CVE-2026-23489) in the GLPI Fields plugin that could allow privileged users to drop shells via a form field, but no PoC, exploit code, patch, or active exploitation is reported.

    0001070
    151 followersView on X
  • cybrmonk@cybr_monk
    Exploit

    GLPI “Fields” Plugin Remote Code Execution: Exploit Code Now Public for CVE-2026-23489 https://cybrmonk.com/blog/glpi-fields-plugin-remote-code-execution-exploit-code-now-public-for-cve-2026-23489 #cybersecurity #threatintelligence https://t.co/DcmveEGmSL

    Post summary

    The text announces that public exploit code is now available for CVE-2026-23489, a Remote Code Execution vulnerability in the GLPI Fields Plugin, pointing to a blog post with further details.

    0000052
    47 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23489 Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users t… https://www.cve.org/CVERecord?id=CVE-2026-23489

    Post summary

    CVE-2026-23489 discloses that the GLPI Fields plugin (pre‑v1.23.3) permits arbitrary PHP code execution via custom fields, but no PoC, exploit code, active attacks, or patch information are provided.

    00000117
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appteclib-editionfields-glpi-

Explore more