CVE-2026-53629
HighPublished
GLPI: SQL injection in history tab
- Published
- Sep 25, 2026
- Updated
- Sep 25, 2026
- Assigning CNA
- GitHub_M
- Evidence observed
- Aug 6, 2026
Primary CVSS
7.1/ 10High
nvd · CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSummary
GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL for the history tab that injects attacker-controlled values into a database query. This permits SQL injection through the history tab endpoint. This issue is fixed in versions 11.0.8 and 10.0.26.
Sources
Repository evidence: Files: 1 · Repositories: 1
1 Template
http/cves/2026/CVE-2026-53629.yaml
Nuclei TemplatesDeclared conditions
- network: http($.protocol_keys)
- verification: dsl,word($.matchers[*].type)
- glpi-logbleedExploit
PoC for CVE-2026-53629, blind SQL injection in the GLPI history log filter
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.