CVE-2026-45801EPSS p22.0%
CVE-2026-45801CVE-2026-45801
Description
GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission can enable debug mode. The affected user-setting update does not enforce the privilege boundary intended to restrict debug-mode activation. This issue is fixed in versions 11.0.8 and 10.0.26.
Scoring
| EPSS | 0.31% probability of exploitation · percentile 22.0% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-25 |