Deux nouvelles versions de GLPI sont disponibles
11.0.8 and 10.0.26 releases fix several critical security issues that have been recently discovered. Update is stronglyrecommended!
De nombreux correctifs ont également été apportés ; consultez les journaux des modifications pour plus de détails :
Vous pouvez télécharger les nouvelles archives sur GitHub :
Vous trouverez ci-dessous la liste des failles de sécurité corrigées dans ces versions correctives :
- [SECURITY - ==Medium== 10.0 & 11.0] Unauthorized debug mode activation (CVE-2026-45801)
- [SECURITY - ==Medium== 10.0 & 11.0] LDAP filter injection in user import feature (CVE-2026-49469)
- [SECURITY - ==Medium== 10.0 & 11.0] Unallowed authentication method update by administrator (CVE-2026-53628)
- [SECURITY - ==Medium== 11.0] Unexpected access to update operations through the API (CVE-2026-53627)
- [SECURITY - ==Medium== 10.0 & 11.0] Unallowed modfication of knowbase items comments and translations (CVE-2026-55217)
- [SECURITY - ==Medium== 10.0 & 11.0] Unallowed notifications sending (CVE-2026-57152)
- [SECURITY - ==High== 10.0 & 11.0] SQL injection in dropdowns (CVE-2026-47678)
- [SECURITY - ==High== 10.0 & 11.0] Arbitrary file deletion (CVE-2026-47679)
- [SECURITY - ==High== 11.0] Account takeover via 2FA brute force (CVE-2026-49470)
- [SECURITY - ==High== 10.0 & 11.0] Privilege Escalation via authtype API manipulation (CVE-2026-53625)
- [SECURITY - ==High== 11.0] Reflected XSS in dashboards (CVE-2026-53610)
- [SECURITY - ==High== 11.0] Arbitrary document read (CVE-2026-53626)
- [SECURITY - ==High== 10.0 & 11.0] SQL injection in history tab (CVE-2026-53629)
- [SECURITY - ==High== 11.0] Stored XSS in suppliers (CVE-2026-55214)
- [SECURITY - ==CRITICAL== 11.0] RCE via Form import (CVE-2026-48482)
- [SECURITY - ==CRITICAL== 11.0] MFA bypass (CVE-2026-52848)
Nous tenons à remercier toutes les personnes qui ont contribué à cette nouvelle version ainsi que tous ceux qui contribuent régulièrement au projet GLPI !
