{"id":"CVE-2026-53626","summary":"GLPI: Arbitrary Document Read via Form Context Authorization Bypass","details":"GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. A user can use an unrelated item that the user is permitted to view to read a document linked to an inaccessible item. This issue is fixed in version 11.0.8.","aliases":["GHSA-q9rc-v6vm-q5mm"],"modified":"2026-09-27T03:47:32.777144173Z","published":"2026-09-25T18:37:53.046Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-639","CWE-862"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53626.json"},"references":[{"type":"WEB","url":"https://github.com/glpi-project/glpi/releases/tag/11.0.8"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53626.json"},{"type":"ADVISORY","url":"https://github.com/glpi-project/glpi/security/advisories/GHSA-q9rc-v6vm-q5mm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53626"},{"type":"FIX","url":"https://github.com/glpi-project/glpi/commit/e984bf1ba435cee7319679df842c61b756baf191"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/glpi-project/glpi","events":[{"introduced":"8b075d544b3e4c28f8ba51ce8dd10e57be924172"},{"fixed":"e984bf1ba435cee7319679df842c61b756baf191"},{"fixed":"1056d00af818ad2a99e3009a21a9db8c724ddc53"}],"database_specific":{"extracted_events":[{"introduced":"11.0.5"},{"fixed":"11.0.8"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["11.0.7","11.0.6","11.0.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53626.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}