CVE-2026-53625
GLPI: Privilege Escalation via authtype API manipulation
- Published
- Sep 25, 2026
- Updated
- Sep 25, 2026
- Assigning CNA
- GitHub_M
- Evidence observed
- Aug 8, 2026
Primary CVSS
cvelist · CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NSummary
GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another user's authentication method. Under configurations using the legacy API REST interface or SSO logins, this can change a super-administrator's authentication method and enable account takeover. This issue is fixed in versions 11.0.8 and 10.0.26.
Sources
GLPI Privilege Escalation via authtype Manipulation PoC - CVE-2026-53625. Ethical PoC for the GLPI vulnerability allowing a Technician to take full control of any Super-Admin account through REST API authtype manipulation.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.