Tech News

GLPI 11.0.10 and 10.0.28 Patch 8 Flaws as GLPI 10 Reaches End of the Line

Just two weeks after its previous round of security fixes, Teclib' has released GLPI 11.0.10 and GLPI 10.0.28. The update includes 8 security flaws fixed and an announcement for organizations still running GLPI 10. Here’s what you need to know.

On September 30, 2026, two new versions were published on GitHub: GLPI 11.0.10 for the current branch, and GLPI 10.0.28 for the previous branch. In both cases, these are security updates.

A few days ago, I published an article about GLPI 11.0.9 and 10.0.27, which fixed 12 flaws including a SQL injection exploitable without authentication. When those previous versions were released, Teclib' announced that it would speed up its release cadence, notably because AI is accelerating flaw discovery and increasing the number of issues to address. "Expect security releases about every two weeks," the company said. The previous release dates from September 16, and this one from September 30. So here we are.

Eight security flaws in GLPI 11, six in GLPI 10

The new GLPI 11 release, namely GLPI 11.0.10, fixes 8 vulnerabilities: 6 are rated important and 2 moderate. GLPI 10.0.28 fixes 6, all shared between the two branches. At the time of writing, no CVE identifier has been assigned to these flaws.

The six flaws shared by GLPI 10 and GLPI 11:

  • Authorization bypass in bulk actions (important): these actions are used to apply a change to multiple items in a single operation. A faulty control at this level could allow actions beyond a user’s permissions.
  • Privilege escalation through user cloning (important): cloning an account could be abused to obtain higher privileges than intended.
  • Insufficient access control when deleting users (important): user accounts could be deleted by someone without the required authorization.
  • SQL injection via the forms “Actors” question (important): in GLPI 11’s native forms engine, this question type lets users choose users or groups as requester, observer, or technician. The dropdown sent filtering criteria for groups to the server, which were inserted into the SQL query without validation.
  • Username enumeration through the calendar (moderate): this could be used to retrieve a list of valid usernames, information that is useful when preparing a brute-force attack.
  • Missing authorization checks in the calendar (moderate): a second permissions issue in the same feature.

Two additional flaws are specific to GLPI 11:

  • Disabling or changing 2FA for more privileged users (important): a user could interfere with two-factor authentication on accounts that have higher privileges than their own.
  • Reflected XSS in the dashboard search results widget (important): as with any reflected XSS, exploitation generally requires a crafted request that the victim must open.

What stands out is that 5 flaws stem from a security problem in authorization checks.

GLPI 10.0.28, the final version of the 10 branch

Beyond the release of these versions, there is another important piece of information highlighted by Teclib' in the announcement published on the GLPI blog. "With the upcoming release of GLPI 12.0.0, version 10.0.28 will be the last release in the 10.0 branch, which will no longer receive patches," Teclib' states.

So, if you are still on GLPI 10, install version 10.0.28 now: this will be your last patch. More importantly, plan a migration to a maintained and newer version. Indeed, over the past several months, we have seen that most vulnerabilities affected both branches: GLPI 10 and GLPI 11. What I want to tell you is that the next vulnerabilities discovered in shared code will therefore remain unpatched on GLPI 10. With releases roughly every two weeks, the security gap of a GLPI 10 instance will widen very quickly.

To apply these fixes, you can follow my tutorial how to update GLPI, with a step-by-step process that starts with the backup. For those preparing the migration, I also covered the main new features in GLPI 11. Keep in mind that GLPI 12 is planned for October 2026.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.