CVE-2026-53626
— UNSCOREDpublic exploit availablePublished 2026-09-25 · Updated 2026-09-30
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. A user can use an unrelated item that the user is permitted to view to read a document linked to an inaccessible item. This issue is fixed in version 11.0.8.
Weaknesses
CWE-639, CWE-862
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-52850PoC
- UNSCOREDCVE-2026-56724PoC
- MEDIUMCVE-2026-61748PoC
- UNSCOREDCVE-2026-63204PoC
- UNSCOREDCVE-2026-63205PoC
- MEDIUMCVE-2026-69190PoC
- HIGHCVE-2026-76087PoC
- HIGHCVE-2026-76089PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.