Authenticated path traversal leads to arbitrary file deletion. This vulnerability was identified using a custom agentic security workflow. Original vulnerability report here.
Disclosure Timeline:
- 2026-05-14: Initial report sent to GLPI Team via Github.
- 2026-05-18: GLPI Team acknowledges and verifies the vulnerability.
- 2026-05-19: CVE is assigned.
Mitigation
Upgrade to 10.0.26 or 11.0.8.