/var/www arbitrary-file-deletion-in-glpi

Advisories ~0 min read

Arbitrary file deletion in GLPI

Any logged GLPI user can request a deletion of any file hosted by the server. CVE-2026-47679

Authenticated path traversal leads to arbitrary file deletion. This vulnerability was identified using a custom agentic security workflow. Original vulnerability report here.

Disclosure Timeline:

  • 2026-05-14: Initial report sent to GLPI Team via Github.
  • 2026-05-18: GLPI Team acknowledges and verifies the vulnerability.
  • 2026-05-19: CVE is assigned.

Mitigation

Upgrade to 10.0.26 or 11.0.8.

back to /var/www