Two new GLPI versions are available!
Today, we ship 11.0.7 y 10.0.25. These releases contain security fixes, and we encourage you to update.
Many bug fixes have also been made. Read the changelogs for more details:
You can download the new archives on GitHub:
You will find below the list of security issues fixed in these bugfix versions:
- [SECURITY - Low 10.0 & 11.0] Unauthorized update of configuration
- [SECURITY - Low 10.0 & 11.0] Unauthorized IMAP connection probing
- [SECURITY - Low 11.0] Unauthorized reading of a specific asset object
- [SECURITY - Low 11.0] Unauthorized modification of webhook payload templates
- [SECURITY - Low 11.0] Unauthorized Webhook CRA Validation SSRF
- [SECURITY - Low 11.0] Webhook CRA signature bypass
- [SECURITY - Low 11.0] Unauthorized resending of queued webhooks
- [SECURITY - Medium 11.0] Unauthorized export of form structure (CVE-2026-32312)
- [SECURITY - Medium 10.0 & 11.0] Arbitrary files access (CVE-2026-42320)
- [SECURITY - High 10.0] Stored XSS in asset locks (CVE-2026-42321)[SECURITY - High 11.0] Stored XSS in knowledge base (CVE-2026-5385)
- [SECURITY - High 11.0] Stored XSS in ITIL Costs (CVE-2026-40108)
- [SECURITY - High 10.0 & 11.0] Arbitrary item deletion via planning (CVE-2026-42318)
- [SECURITY - High 10.0 & 11.0] Arbitrary files deletion by technician (CVE-2026-42317)
We would like to thank all people who contributed to this new version and all those who contribute regularly to the GLPI project!
Regards.
