This release includes a security fix related to CVE-2023-34254. You’ll only be concerned by this security alert if you’re using the remoteinventory task in the case of unix/linux remote inventory via ssh.
Here is a summary of the most important changes:
libxml2 library is now required for all the features using XML,
Windows keystore support has been extended to support more stores to ease GLPI SSL certificate validation,
inventory task has a lot of enhancements. In particular, some WMI timeouts has been fixed on windows and a new assetname-support option permits to choose to set asset name from short hostname or fqdn on unix/linux,
remoteinventory task includes several important fixes and has been enhanced to support remote inventory multi-threading thanks to the new remote-workers option,
netdiscovery and netinventory tasks also had their bunch of fixes and many new devices are now supported,
deploy, collect and ESX tasks also had few fixes and enhancements,
the embedded HTTPD interface can now use a basic authentication plugin to secure even more access, like for the ToolBox interface,
MacOSX packages have been updated to use OpenSSL 3.1.1 and zlib 1.2.13,
the 3.5 version of dmidecode has been included in windows and MacOSX packages,
the linux perl installer includes several fixes and now supports Oracle Linux 7 installation,
MSI packaging now permits to install GLPI-AgentMonitor community tool which provides interesting features for users via a systray icon, check the following project for more details: https://github.com/glpi-project/glpi-agentmonitor
Speaking about the MSI packaging, we decided to not sign the packages and provided binaries as code-signing SSL certificate providers are failing to provide us the required certificate in a reasonable time. So you may experience some security alerts until the MSI packages reputation has been nicely established.
The most important one fixes a regression introduced in GLPI-Agent v1.3 which prevents windows or macosx agents to communicate with HTTPS GLPI server using a publicly signed SSL certificate.
For the other ones:
new ssl-fingerprint option feature now also works on CentOS7,
on SSL communication error, the agent will report a more explicit reason,
we added support for linux systemd-nspawn container inventory,
we added a new Acer monitor model support: B226WL,
we fixed the support of non-standard port for ssh remote inventory,
the MacOSX packages have been upgraded to use OpenSSL 3.0.4,
the linux perl installer now support installation on Oracle Linux 8.
As always, you can check the more detailed changelog at:
This release includes some fixes and enhancements. Here are the most important ones:
we implemented a feature request from the community to support SSL server certificate of the GLPI server deployment with operating system deployment feature:
on windows, the glpi server certificate can be deployed through the enterprise keystore,
on macosx, the glpi server certificate can be deployed in system keychain through a MDM.
we added the support of the new ‘ssl-fingerprint’ option and it permits to trust a GLPI server certificate without the need of deploying a certificate:
you can first enable one time the ‘no-ssl-check’ option on one agent to find the related ssl fingerprint reported in agent log,
then you can set the discovered value for all your agents and disable ‘no-ssl-check’ on the first one.
the windows MSI packaging is now using Perl 5.36.0 and includes some fixes and improvements:
as it was wrongly creating firewall rules, this is fixed and wrong rules are removed,
few libraries was missing if you wanted to use SNMPv3 authentication during network discovery or inventory,
the installer was failing to create the windows task when you wanted to use windows task scheduling,
few configurations was not possible during silent installation.
the MacOSX packages has been upgraded to use Perl 5.36.0, OpenSSL 3.0.3 & zlib 1.2.12 and the installation on APFS filesystem has also been fixed.
for linux packaging, we have also few big improvements:
AppImage support for older linux like CentOS 7,
AppImage uninstallation process has been improved,
Snap packaging has been upgraded to use Perl 5.36.0,
perl linux installer has been enhanced to support installation on openSUSE.
For inventory task, we integrated:
a patch from the community which can fix monitor inventory on linux,
an Oracle database inventory support update,
an update to avoid false positive antivirus alert during software inventory on windows,
a fix on JSON format support to avoid wrongly encoded strings on macosx,
a fix against a JSON validation error while monitor serial is an integer,
a fix on generated partial inventory as the ‘partial’ property was missing,
an update for additional-content option support while using JSON format.
RemoteInventory task has been improved so remote ssh inventory of linux/unix platforms can fallback on ssh command calls when libssh2 is not available.
Netdiscovery and NetInventory tasks now includes a module from the community which enhances DefensePro support.
The professional support for GLPI Android Inventory Agent and GLPI is available through our Partners´ Network for the customers covered by GLPI Network Subscription. Obtain a personalised professional support by contacting us: click
Interconnection
GLPI Android Inventory Agent is interconnected with GLPI and FusionInventory plugin.
Use CMDB management with GLPI and FusionInventory inventory rules to manage easily your Android-based mobile fleet.
GLPI plugin “Agent Config” allows you to easily configure (server and inventory frequency) the agent via QR Code or DeepLink (only available under GLPI Network subscription)
This new version fixes the following security issues:
[SECURITY - High] MySQL client option-file injection via unsanitized server-supplied credential fields (CVE-2026-TODO)
[SECURITY - Low] Proxy plugin can allow any system .xml file overwrite if local_store is enabled
We strongly encourage you to update your agents.
Bug fixes and enhancements
The release also includes some bug fixes and enhancements. Here are the more important ones:
On MacOSX, a bug involving cpu usage overloading was fixed
OAuth2 authentication credentials can be defined as a comma separated list to support more than one server target
A windows network inventory regression was introduced in v1.19. This version fixes it.
For netdiscovery/netinventory tasks:
on windows, we fixed a cpu usage overloading due to iec61850 protocol support
as a big optimization, glpi-agent will now test by default each device to know if it supports bulk snmp requests. This drastically reduces inventory time on big routers.
inventory of Siemens devices with SNMP v3 credentials won’t no more fail on privacy protocol during netdiscovery when more than one possible credentials are tested
New options are introduced to debug iec61850 protocol support
For Proxy server plugin:
Pending status are now fetched as expected when using chained glpi-agent proxies
we fixed again XML content-type support for inventories sent by android agent as accidentally reverted in v1.17
For ToolBox:
Scheduled jobs are now planified as expected when service is started or restarted
Packaging
About packaging, here is what you should retain:
On windows, GLPI Agent uses OpenSSL 3.5.8, updated building toolchain, libxml2 2.15.4, 7-zip v26.03, Glpi-AgentMonitor 1.5.1 and libssh2 1.11.1 patched for CVE-2025-15661, CVE-2026-7598, CVE-2026-55199, CVE-2026-55200, CVE-2026-58050, CVE-2026-58051, CVE-2026-66032, CVE-2026-66033, CVE-2026-66034 and CVE-2026-66035
The MacOSX packaging now uses OpenSSL 3.5.8 and getaddrinfo native support is disabled in built perl to avoid crashes on tahoe
We strongly encourage you to update your agents to ensure optimal security and operational performance.
We are pleased to announce the availability of OAuth authentication in GLPI Android Inventory Agent 1.9.0.
This new feature enhances the security of Android deployments by providing a modern, dedicated authentication mechanism specifically designed for inventory operations.
More Secure and Dedicated Authentication
With this new version, administrators can configure a dedicated OAuth client for GLPI Android Inventory Agent, with the permissions and scope required for inventory operations.
This approach makes it possible to:
Limit the permissions granted to the agent to only those required for inventory operations;
Dedicate an OAuth client specifically to Android devices and inventory operations;
Reduce the attack surface by avoiding broader authentication mechanisms than necessary;
Centralize and simplify access management directly from GLPI.
Secure Android Inventory
OAuth authentication allows GLPI Android Inventory Agent to securely authenticate with GLPI when transmitting inventory data.
By using an OAuth client specifically dedicated to inventory operations, organizations can implement an authentication architecture that meets their security requirements while maintaining a simple deployment experience for both users and administrators.
This enhancement is particularly relevant for organizations managing a large Android device fleet, operating in security-sensitive environments, or enforcing strict access management policies.
Dedicated Documentation
Comprehensive documentation is now available to guide administrators through the configuration and deployment process:
We invite our partners, customers, and members of the GLPI community to discover this new feature and adopt GLPI Android Inventory Agent 1.9.0 for deployments requiring OAuth authentication.
Upgrade to version 1.9.0 today and strengthen the security of your Android inventory deployments with dedicated, modern, and purpose-built OAuth authentication.
Removed ServiceForeground which caused a crash on Android 14
Fixed a crash with registerReceiver
Improvement
Scheduler
The task scheduler executing automatic inventory has been rewritten using JobScheduler.
This allows Android to determine the optimal time to run the automatic inventory within the defined interval (day, week, month), while complying with Android recommendations on battery usage, mobile network access, etc.
Notification
The notification engine has been rewritten to comply with Android best practices.
From Android 13, you will be asked to allow notifications on the first launch.
(You can revisit this setting in your Android device's notification settings).
Permissions
The permission process has been rewritten for better compatibility with the latest version of Android.
Don't forget!
The GLPI agent can be deployed/configured from an MDM/EMM tool such as:
Samsung Knox
AirWatch
InTunes
MobileIron
etc.
As long as the MDM/EMM tool supports managed configurations, you can configure the GLPI Agent (at deployment or on-the-fly).
Compatibility
Android
EMM / MDM compatibility implies a change in the minimum Android version supported by the Android application.
You now need a device running at least Android 5 Lollipop (Sdk 21), and the agent is compatible up to Android 14 Upside Down Cake (Sdk 34).
Pour offrir les meilleures expériences, nous utilisons des technologies telles que les cookies pour stocker et/ou accéder aux informations des appareils. Le fait de consentir à ces technologies nous permettra de traiter des données telles que le comportement de navigation ou les ID uniques sur ce site. Le fait de ne pas consentir ou de retirer son consentement peut avoir un effet négatif sur certaines caractéristiques et fonctions.
Fonctionnel
Always active
L’accès ou le stockage technique est strictement nécessaire dans la finalité d’intérêt légitime de permettre l’utilisation d’un service spécifique explicitement demandé par l’abonné ou l’utilisateur, ou dans le seul but d’effectuer la transmission d’une communication sur un réseau de communications électroniques.
Préférences
L’accès ou le stockage technique est nécessaire dans la finalité d’intérêt légitime de stocker des préférences qui ne sont pas demandées par l’abonné ou l’internaute.
Statistiques
Le stockage ou l’accès technique qui est utilisé exclusivement à des fins statistiques.Le stockage ou l’accès technique qui est utilisé exclusivement dans des finalités statistiques anonymes. En l’absence d’une assignation à comparaître, d’une conformité volontaire de la part de votre fournisseur d’accès à internet ou d’enregistrements supplémentaires provenant d’une tierce partie, les informations stockées ou extraites à cette seule fin ne peuvent généralement pas être utilisées pour vous identifier.
Marketing
L’accès ou le stockage technique est nécessaire pour créer des profils d’internautes afin d’envoyer des publicités, ou pour suivre l’utilisateur sur un site web ou sur plusieurs sites web ayant des finalités marketing similaires.