CVE-2026-53625EPSS p45.3%
CVE-2026-53625CVE-2026-53625
Description
GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another user's authentication method. Under configurations using the legacy API REST interface or SSO logins, this can change a super-administrator's authentication method and enable account takeover. This issue is fixed in versions 11.0.8 and 10.0.26.
Scoring
| EPSS | 0.57% probability of exploitation · percentile 45.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-25 |