CVE-2026-26026Patch(glpi-project / glpi)

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch glpi-project glpi systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-1336

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • glpi

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Products
glpi

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-06: 4PoC Mentioned / Linked · 2026-04-06: 1Patch / Workaround · 2026-04-06: 3Technical Details · 2026-04-06: 404-06
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-26026: CRITICAL] GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6.#cve,CVE-2026-26026,#cybersecurity https://cvefind.com/CVE-2026-26026

    Post summary

    GLPI’s CVE‑2026‑26026 is a critical RCE vulnerability caused by template injection for administrators; it has been fixed in version 11.0.6, with details provided on the CVEFind page.

    0000062
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-26026 GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed… https://www.cve.org/CVERecord?id=CVE-2026-26026 ----- Traducción: CVE-2026-26026 GLP… http://infoflow.cloud`

    Post summary

    The announcement describes CVE‑2026‑26026 in GLPI that enables administrators to perform template injection resulting in remote code execution, but notes that the issue has already been patched.

    0000048
    67 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-26026 GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed… https://www.cve.org/CVERecord?id=CVE-2026-26026

    Post summary

    The CVE‑2026‑26026 vulnerability in GLPI (template injection -> RCE) prior to version 11.0.6 has been resolved, but no PoC, exploit, or active attacks are disclosed.

    00000189
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-26026: GLPI... Admin-to-RCE via double template compilation in GLPI 11.0.0-11.0.5 - classic Twig injection with a twist that bypasses standard filters #SSTI #RCE. https://zerodaysignal.com/vulnerability/CVE-2026-26026 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces the discovery of CVE-2026-26026 in GLPI, outlining an admin‑to‑RCE via double template compilation and referencing a link for further details.

    0000062
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appglpi-projectglpi---

Explore more