CVE-2026-53625: GLPI-Project GLPI

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another user's authentication method. Under configurations using the legacy API REST interface or SSO logins, this can change a super-administrator's authentication method and enable account takeover. This issue is fixed in versions 11.0.8 and 10.0.26.

Affected products

  • GLPI-Project GLPI: from 0.70, before 10.0.26 (fixed in 10.0.26); from 11.0.0, before 11.0.8 (fixed in 11.0.8)

Published 2026-09-25. Last modified 2026-09-25.