CVE-2026-26001

The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, non sanitized user input can lend to an SQL injection from reports, with adequate rights. This vulnerability is fixed in 1.6.6.
Configurations

Configuration 1 (hide)

cpe:2.3:a:glpi-project:glpi_inventory:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-18 00:16

Updated : 2026-03-23 18:14


NVD link : CVE-2026-26001

Mitre link : CVE-2026-26001

CVE.ORG link : CVE-2026-26001


JSON object : View

Products Affected

glpi-project

  • glpi_inventory
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')