CVE-2026-48482 Details
Description
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset directory. The imported file can be written to an executable server location, allowing a malicious script to be invoked remotely. This issue is fixed in version 11.0.8.
A remote code execution vulnerability has been identified in GLPI versions 11.0.0 prior to 11.0.8. The issue arises when a form administrator uses the Form import feature with a manipulated illustration or scene identifier that escapes the designated custom-asset directory. This allows the imported file to be saved in an executable location on the server, where a malicious script could be executed remotely.
Users are advised to upgrade to GLPI version 11.0.8, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/glpi-project/glpi/commit/d817cb5c17e3368c89d4a561a43a777662b9da19 | [email protected] | Source CodeVendor |
| https://github.com/glpi-project/glpi/releases/tag/11.0.8 | [email protected] | Release NotesVendor |
| https://github.com/glpi-project/glpi/security/advisories/GHSA-6whc-g4h2-98rm | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GLPI | >= 11.0.0, <= 11.0.8 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 25, 2026 | New CVE Received | [email protected] |
Volerion