GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthorized forms. This issue has been fixed in version 11.0.7.
History

Tue, 19 May 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Glpi-project
Glpi-project glpi
Vendors & Products Glpi-project
Glpi-project glpi

Tue, 19 May 2026 00:15:00 +0000

Type Values Removed Values Added
Description GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthorized forms. This issue has been fixed in version 11.0.7.
Title GLPI: Unauthorized export of form structure
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-05-18T23:46:26.200Z

Updated: 2026-05-18T23:46:26.200Z

Reserved: 2026-03-11T21:16:21.660Z

Link: CVE-2026-32312

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-19T00:16:37.283

Modified: 2026-05-19T00:16:37.283

Link: CVE-2026-32312

cve-icon Redhat

No data.