Two new GLPI versions are available.
These updates fix a recently discovered critical security vulnerability. Updating is highly recommended!
You can download the GLPI 11.0.6 archive on GitHub.
You will find below the list of security issues fixed in this bugfixes version:
- [SECURITY - Critical] Server-Side Template Injection (CVE-2026-26026)
- [SECURITY - High] Stored XSS via Inventory (CVE-2026-26027)
- [SECURITY - High] Unauthenticated SQL Injection via Search engine (CVE-2026-26263)
- [SECURITY - High] Authenticated SQL Injection (CVE requested)
- [SECURITY - Moderate] MFA bypass (CVE-2026-25937)
- [SECURITY - Moderate] Authenticated SQL Injection (CVE-2026-25936)
Also, here is a short list of important bug fixes included in this version:
- Fix linked ITIL objects visibility across entities and rights verification #22851
- Fix timeline crash when document dates are NULL #22134
- Fix Error creating template #23034
- Fix error creating ticket #22984
The full changelog is available for more details.
Also, an XSS ([SECURITY - High] Stored XSS in Supplier CVE-2026-25932) and [SECURITY - High] Authenticated SQL Injection (CVE requested) have been detected on 10.0 branch, so a new version is also available today.
You can download the GLPI 10.0.24 archive on GitHub.
We would like to thank all people who contributed to this new version and all those who contributes regularly to the GLPI project!
Regards.
