This release includes a security fix related to CVE-2023-34254. You’ll only be concerned by this security alert if you’re using the remoteinventory task in the case of unix/linux remote inventory via ssh.
Here is a summary of the most important changes:
libxml2 library is now required for all the features using XML,
Windows keystore support has been extended to support more stores to ease GLPI SSL certificate validation,
inventory task has a lot of enhancements. In particular, some WMI timeouts has been fixed on windows and a new assetname-support option permits to choose to set asset name from short hostname or fqdn on unix/linux,
remoteinventory task includes several important fixes and has been enhanced to support remote inventory multi-threading thanks to the new remote-workers option,
netdiscovery and netinventory tasks also had their bunch of fixes and many new devices are now supported,
deploy, collect and ESX tasks also had few fixes and enhancements,
the embedded HTTPD interface can now use a basic authentication plugin to secure even more access, like for the ToolBox interface,
MacOSX packages have been updated to use OpenSSL 3.1.1 and zlib 1.2.13,
the 3.5 version of dmidecode has been included in windows and MacOSX packages,
the linux perl installer includes several fixes and now supports Oracle Linux 7 installation,
MSI packaging now permits to install GLPI-AgentMonitor community tool which provides interesting features for users via a systray icon, check the following project for more details: https://github.com/glpi-project/glpi-agentmonitor
Speaking about the MSI packaging, we decided to not sign the packages and provided binaries as code-signing SSL certificate providers are failing to provide us the required certificate in a reasonable time. So you may experience some security alerts until the MSI packages reputation has been nicely established.
The most important one fixes a regression introduced in GLPI-Agent v1.3 which prevents windows or macosx agents to communicate with HTTPS GLPI server using a publicly signed SSL certificate.
For the other ones:
new ssl-fingerprint option feature now also works on CentOS7,
on SSL communication error, the agent will report a more explicit reason,
we added support for linux systemd-nspawn container inventory,
we added a new Acer monitor model support: B226WL,
we fixed the support of non-standard port for ssh remote inventory,
the MacOSX packages have been upgraded to use OpenSSL 3.0.4,
the linux perl installer now support installation on Oracle Linux 8.
As always, you can check the more detailed changelog at:
This release includes some fixes and enhancements. Here are the most important ones:
we implemented a feature request from the community to support SSL server certificate of the GLPI server deployment with operating system deployment feature:
on windows, the glpi server certificate can be deployed through the enterprise keystore,
on macosx, the glpi server certificate can be deployed in system keychain through a MDM.
we added the support of the new ‘ssl-fingerprint’ option and it permits to trust a GLPI server certificate without the need of deploying a certificate:
you can first enable one time the ‘no-ssl-check’ option on one agent to find the related ssl fingerprint reported in agent log,
then you can set the discovered value for all your agents and disable ‘no-ssl-check’ on the first one.
the windows MSI packaging is now using Perl 5.36.0 and includes some fixes and improvements:
as it was wrongly creating firewall rules, this is fixed and wrong rules are removed,
few libraries was missing if you wanted to use SNMPv3 authentication during network discovery or inventory,
the installer was failing to create the windows task when you wanted to use windows task scheduling,
few configurations was not possible during silent installation.
the MacOSX packages has been upgraded to use Perl 5.36.0, OpenSSL 3.0.3 & zlib 1.2.12 and the installation on APFS filesystem has also been fixed.
for linux packaging, we have also few big improvements:
AppImage support for older linux like CentOS 7,
AppImage uninstallation process has been improved,
Snap packaging has been upgraded to use Perl 5.36.0,
perl linux installer has been enhanced to support installation on openSUSE.
For inventory task, we integrated:
a patch from the community which can fix monitor inventory on linux,
an Oracle database inventory support update,
an update to avoid false positive antivirus alert during software inventory on windows,
a fix on JSON format support to avoid wrongly encoded strings on macosx,
a fix against a JSON validation error while monitor serial is an integer,
a fix on generated partial inventory as the ‘partial’ property was missing,
an update for additional-content option support while using JSON format.
RemoteInventory task has been improved so remote ssh inventory of linux/unix platforms can fallback on ssh command calls when libssh2 is not available.
Netdiscovery and NetInventory tasks now includes a module from the community which enhances DefensePro support.
The professional support for GLPI Android Inventory Agent and GLPI is available through our Partners´ Network for the customers covered by GLPI Network Subscription. Obtain a personalised professional support by contacting us: click
Interconnection
GLPI Android Inventory Agent is interconnected with GLPI and FusionInventory plugin.
Use CMDB management with GLPI and FusionInventory inventory rules to manage easily your Android-based mobile fleet.
GLPI plugin “Agent Config” allows you to easily configure (server and inventory frequency) the agent via QR Code or DeepLink (only available under GLPI Network subscription)
Une nouvelle version de l’agent GLPI est disponible !
Cette nouvelle version corrige la sécurité pour les failles suivantes:
[SECURITÉ - Haute] Injection MySQL dans l’option option-file via des champs non vérifiés fournis par le serveur (CVE-2026-TODO)
[SECURITÉ - Basse] Le plugin Proxy peut permettre d’écraser n’importe quel fichier système avec une extension .xml si local_store est activé
Nous vous encourageons fortement à mettre à jour vos agents.
Corrections de bugs et améliorations
Cette release inclut aussi d’importants correctifs et améliorations. Voici les plus importants :
Sur MacOSX, un bug impliquant un usage important du cpu a été corrigé
Les identifiants pour l’authentification OAuth2 peuvent être définis en une liste de valeurs séparées par des virgules pour supporter plus d’un serveur cible
Une régression de l’inventaire réseau sous Windows avait été introduite en v1.19. Cette version la corrige.
Pour les tâches netdiscovery/netinventory :
sous Windows, nous avons corrigé une surcharge du cpu due à la prise en charge du protocole iec61850
grosse optimisation : l’agent GLPI teste désormais par défaut chaque équipement pour savoir s’il prend en charge les requêtes SNMP bulk. Le temps d’inventaire des gros routeurs est ainsi considérablement réduit.
l’inventaire des équipements Siemens avec des identifiants SNMP v3 n’échoue plus sur le protocole de confidentialité (privacy) lors de la netdiscovery quand plusieurs identifiants possibles sont testés
De nouvelles options sont introduites pour déboguer la prise en charge du protocole iec61850
Pour le plugin serveur Proxy :
Les statuts en attente sont désormais récupérés correctement lors de l’utilisation de proxys glpi-agent chaînés
nous avons de nouveau corrigé la prise en charge du content-type XML pour les inventaires envoyés par l’agent Android, annulée par erreur en v1.17
Pour la ToolBox :
Les tâches planifiées sont désormais programmées correctement au démarrage ou au redémarrage du service
Paquets
Au niveau des paquets, voici ce qu’il faut retenir :
Sur Windows, l’agent GLPI utilise OpenSSL 3.5.8, une chaîne de compilation mise à jour, libxml2 2.15.4, 7-zip v26.03, Glpi-AgentMonitor 1.5.1 et la librairie libssh2 1.11.1 patchée pour les CVE suivantes : CVE-2025-15661, CVE-2026-7598, CVE-2026-55199, CVE-2026-55200, CVE-2026-58050, CVE-2026-58051, CVE-2026-66032, CVE-2026-66033, CVE-2026-66034 et CVE-2026-66035
Le paquet MacOSX utilise maintenant OpenSSL 3.5.8 et le support natif de getaddrinfo est désactivé dans perl pour éviter des crashes sur tahoe
Nous vous recommandons vivement de mettre à jour vos agents afin de garantir une sécurité et des performances opérationnelles optimales.
Nous sommes heureux d’annoncer la disponibilité de l’authentification OAuth dans GLPI Android Inventory Agent 1.9.0.
Cette nouvelle fonctionnalité renforce la sécurité des déploiements Android en proposant un mécanisme d’authentification moderne, dédié et mieux adapté aux opérations d’inventaire.
Une authentification plus sécurisée et dédiée
Avec cette nouvelle version, les administrateurs peuvent configurer un client OAuth dédié à GLPI Android Inventory Agent, avec les permissions et le scope nécessaires aux opérations d’inventaire.
Cette approche permet notamment de :
Limit the permissions granted to the agent to only those required for inventory operations;
Dedicate an OAuth client specifically to Android devices and inventory operations;
Reduce the attack surface by avoiding broader authentication mechanisms than necessary;
Centralize and simplify access management directly from GLPI.
Un inventaire Android sécurisé
L’authentification OAuth permet à GLPI Android Inventory Agent de s’authentifier auprès de GLPI de manière sécurisée lors de la transmission des données d’inventaire.
By using an OAuth client specifically dedicated to inventory operations, organizations can implement an authentication architecture that meets their security requirements while maintaining a simple deployment experience for both users and administrators.
Cette évolution est particulièrement pertinente pour les environnements disposant d’un parc Android important, de contraintes de sécurité élevées ou de politiques strictes de gestion des accès.
Une documentation dédiée
Une documentation complète est désormais disponible afin d’accompagner les administrateurs à chaque étape de la mise en œuvre :
Nous invitons nos partenaires, clients et membres de la communauté GLPI à découvrir cette nouvelle fonctionnalité et à adopter GLPI Android Inventory Agent 1.9.0 pour leurs déploiements nécessitant une authentification OAuth.
Passez dès maintenant à la version 1.9.0 et renforcez la sécurité de vos déploiements d’inventaire Android grâce à une authentification OAuth dédiée, moderne et adaptée aux besoins de votre environnement.
Removed ServiceForeground which caused a crash on Android 14
Fixed a crash with registerReceiver
Improvement
Scheduler
The task scheduler executing automatic inventory has been rewritten using JobScheduler.
This allows Android to determine the optimal time to run the automatic inventory within the defined interval (day, week, month), while complying with Android recommendations on battery usage, mobile network access, etc.
Notification
The notification engine has been rewritten to comply with Android best practices.
From Android 13, you will be asked to allow notifications on the first launch.
(You can revisit this setting in your Android device's notification settings).
Permissions
The permission process has been rewritten for better compatibility with the latest version of Android.
Don't forget!
The GLPI agent can be deployed/configured from an MDM/EMM tool such as:
Samsung Knox
AirWatch
InTunes
MobileIron
etc.
As long as the MDM/EMM tool supports managed configurations, you can configure the GLPI Agent (at deployment or on-the-fly).
Compatibility
Android
EMM / MDM compatibility implies a change in the minimum Android version supported by the Android application.
You now need a device running at least Android 5 Lollipop (Sdk 21), and the agent is compatible up to Android 14 Upside Down Cake (Sdk 34).
Pour offrir les meilleures expériences, nous utilisons des technologies telles que les cookies pour stocker et/ou accéder aux informations des appareils. Le fait de consentir à ces technologies nous permettra de traiter des données telles que le comportement de navigation ou les ID uniques sur ce site. Le fait de ne pas consentir ou de retirer son consentement peut avoir un effet négatif sur certaines caractéristiques et fonctions.
Fonctionnel
Toujours activé
L’accès ou le stockage technique est nécessaire pour la finalité d’intérêt légitime de permettre l’utilisation d’un service expressément demandé par l’abonné ou l’utilisateur, ou dans le seul but de réaliser la transmission d’une communication via un réseau de communications électroniques.
Préférences
L'accès ou le stockage technique est nécessaire pour la finalité de l'intérêt légitime de stocker des préférences qui ne sont pas demandées par l'abonné ou l'internaute.
Statistiques
Le stockage ou l'accès technique qui est utilisé exclusivement à des fins statistiques.Le stockage ou l'accès technique utilisé exclusivement à des fins statistiques anonymes. En l'absence d'une assignation à comparaître, d'une conformité volontaire de la part de votre fournisseur d'accès à Internet ou d'enregistrements supplémentaires provenant d'une tierce partie, les informations stockées ou extraites à cette seule fin ne peuvent généralement pas être utilisées pour vous identifier.
Marketing
L’accès ou le stockage technique est nécessaire pour créer des profils d’utilisateurs afin d’envoyer des publicités, ou pour suivre l’utilisateur sur un site web ou sur plusieurs sites web ayant des objectifs marketing similaires.