CVE-2026-49470
— UNSCOREDpublic exploit availablePublished 2026-09-25 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not limit failed submissions per user. An attacker who has obtained a user's primary authentication credentials can repeatedly submit TOTP values against the MFA verification flow, making brute-force compromise of the second factor and subsequent account takeover possible. This issue is fixed in version 11.0.8.
Weaknesses
CWE-307
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-100501PoC
- MEDIUMCVE-2026-100678PoC
- HIGHCVE-2026-102334PoC
- MEDIUMCVE-2026-37603PoC
- LOWCVE-2026-40538
- UNSCOREDCVE-2026-46649PoC
- MEDIUMCVE-2026-56592
- MEDIUMCVE-2026-56682PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.