CVE-2026-45801
— UNSCOREDpublic exploit availablePublished 2026-09-25 · Updated 2026-09-25
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission can enable debug mode. The affected user-setting update does not enforce the privilege boundary intended to restrict debug-mode activation. This issue is fixed in versions 11.0.8 and 10.0.26.
Weaknesses
CWE-269
Public exploit & PoC references
- https://github.com/glpi-project/glpi/commit/e9d8765122aafda5c61eba33bcbd8323569c8a53
- https://github.com/glpi-project/glpi/commit/fb72d60cfc0e155f8f7707f0a2398bd5f17d7071
- https://github.com/glpi-project/glpi/releases/tag/10.0.26
- https://github.com/glpi-project/glpi/releases/tag/11.0.8
- https://github.com/glpi-project/glpi/security/advisories/GHSA-3vhr-7p54-cqhw
All references
- https://github.com/glpi-project/glpi/commit/e9d8765122aafda5c61eba33bcbd8323569c8a53
- https://github.com/glpi-project/glpi/commit/fb72d60cfc0e155f8f7707f0a2398bd5f17d7071
- https://github.com/glpi-project/glpi/releases/tag/10.0.26
- https://github.com/glpi-project/glpi/releases/tag/11.0.8
- https://github.com/glpi-project/glpi/security/advisories/GHSA-3vhr-7p54-cqhw
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2025-71421PoC
- HIGHCVE-2026-100578PoC
- HIGHCVE-2026-100586PoC
- MEDIUMCVE-2026-100611PoC
- HIGHCVE-2026-100615PoC
- LOWCVE-2026-100620PoC
- HIGHCVE-2026-100686PoC
- HIGHCVE-2026-100801
Related by shared AI tags and CWE weakness class. Browse the full archive.