CVE-2026-42320
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
03/06/2026
Last modified:
03/06/2026
Description
GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0.7, a technician can read arbitrary files inside the GLPI_DOC_DIR. Upgrade to 10.0.25 or 11.0.7 to receive a patch.
Impact
Base Score 4.0
5.90
Severity 4.0
MEDIUM



