Two new GLPI versions are available!
Today, we ship 11.0.7 and 10.0.25. These releases contain security fixes, and we encourage you to update.
Many bug fixes have also been made. Read the changelogs for more details:
You can download the new archives on GitHub:
You will find below the list of security issues fixed in these bugfix versions:
- [SECURITY - Low 10.0 & 11.0] Unauthorized update of configuration
- [SECURITY - Low 10.0 & 11.0] Unauthorized IMAP connection probing
- [SECURITY - Low 11.0] Unauthorized reading of a specific asset object
- [SECURITY - Low 11.0] Unauthorized modification of webhook payload templates
- [SECURITY - Low 11.0] Unauthorized Webhook CRA Validation SSRF
- [SECURITY - Low 11.0] Webhook CRA signature bypass
- [SECURITY - Low 11.0] Unauthorized resending of queued webhooks
- [SECURITY - Medium 11.0] Unauthorized export of form structure (CVE-2026-32312)
- [SECURITY - Medium 10.0 & 11.0] Arbitrary files access (CVE-2026-42320)
- [SECURITY - High 10.0] Stored XSS in asset locks (CVE-2026-42321)[SECURITY - High 11.0] Stored XSS in knowledge base (CVE-2026-5385)
- [SECURITY - High 11.0] Stored XSS in ITIL Costs (CVE-2026-40108)
- [SECURITY - High 10.0 & 11.0] Arbitrary item deletion via planning (CVE-2026-42318)
- [SECURITY - High 10.0 & 11.0] Arbitrary files deletion by technician (CVE-2026-42317)
We would like to thank all people who contributed to this new version and all those who contribute regularly to the GLPI project!
Regards.
