{"id":"CVE-2026-53626","published":"2026-09-25T19:17:27.670","lastModified":"2026-09-30T01:16:37.700","description":"GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. A user can use an unrelated item that the user is permitted to view to read a document linked to an inaccessible item. This issue is fixed in version 11.0.8.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-639","CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://github.com/glpi-project/glpi/commit/e984bf1ba435cee7319679df842c61b756baf191","tags":[]},{"url":"https://github.com/glpi-project/glpi/releases/tag/11.0.8","tags":[]},{"url":"https://github.com/glpi-project/glpi/security/advisories/GHSA-q9rc-v6vm-q5mm","tags":[]}],"exploitRefs":[{"url":"https://github.com/glpi-project/glpi/commit/e984bf1ba435cee7319679df842c61b756baf191","tags":[]},{"url":"https://github.com/glpi-project/glpi/releases/tag/11.0.8","tags":[]},{"url":"https://github.com/glpi-project/glpi/security/advisories/GHSA-q9rc-v6vm-q5mm","tags":[]}],"hasPoc":true,"ai":null}