CRITICAL 9.4 NVD
CVE-2026-48482
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset directory. The imported file can be written to an executable server location, allowing a malicious script to be invoked remotely. This issue is fixed in version 11.0.8.
References
- https://github.com/glpi-project/glpi/commit/d817cb5c17e3368c89d4a561a43a777662b9da19
- https://github.com/glpi-project/glpi/releases/tag/11.0.8
- https://github.com/glpi-project/glpi/security/advisories/GHSA-6whc-g4h2-98rm
This critical severity vulnerability with a CVSS score of 9.4 was published on 2026-09-25 via NVD.
Risk Timeline
CVE Disclosed2026-09-25 · -1 days ago
Remediation Resources
vulnfeed aggregates 11568 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.