CVE-2026-47679
— UNSCOREDpublic exploit availablePublished 2026-09-25 · Updated 2026-09-25
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path validation in the profile-picture update flow to request deletion of an attacker-selected file hosted by the server. This issue is fixed in versions 11.0.8 and 10.0.26.
Weaknesses
CWE-22
Public exploit & PoC references
- https://github.com/glpi-project/glpi/commit/54306faf6a724321ba82c53c7c07ff6612a0d832
- https://github.com/glpi-project/glpi/commit/78ec583051bac3c1b3f9d21729c55cac62afa2f3
- https://github.com/glpi-project/glpi/releases/tag/10.0.26
- https://github.com/glpi-project/glpi/releases/tag/11.0.8
- https://github.com/glpi-project/glpi/security/advisories/GHSA-x5r8-r6vj-79cw
All references
- https://github.com/glpi-project/glpi/commit/54306faf6a724321ba82c53c7c07ff6612a0d832
- https://github.com/glpi-project/glpi/commit/78ec583051bac3c1b3f9d21729c55cac62afa2f3
- https://github.com/glpi-project/glpi/releases/tag/10.0.26
- https://github.com/glpi-project/glpi/releases/tag/11.0.8
- https://github.com/glpi-project/glpi/security/advisories/GHSA-x5r8-r6vj-79cw
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2017-20284
- MEDIUMCVE-2024-58386PoC
- MEDIUMCVE-2025-1280
- HIGHCVE-2025-1281
- HIGHCVE-2025-14753
- HIGHCVE-2026-100372PoC
- HIGHCVE-2026-100520PoC
- MEDIUMCVE-2026-100533PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.