Medium severity4.3NVD Advisory· Published Oct 11, 2026· Updated Oct 11, 2026
CVE-2026-108726
CVE-2026-108726
Description
GLPI through 12.0.0 contains a missing authorization vulnerability in ajax/map.php that allows authenticated low-privileged users to search itemtypes they cannot view by omitting the canView() check. Attackers can submit crafted itemtype and search criteria for types like Contact, Supplier, Contract and Budget to obtain match counts, titles and coordinates within their entities.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=12.0.0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.