Tech News

GLPI 11.0.9 and 10.0.27 Patch 12 Flaws as Update Cadence Accelerates

A security update every two weeks: this is the new pace GLPI administrators need to prepare for. Teclib' has just released GLPI 11.0.9 and GLPI 10.0.27, which fix 12 vulnerabilities, including an unauthenticated SQL injection. Here's what you need to know.

As a reminder, GLPI is the open source asset and service desk management solution maintained by the French vendor Teclib'. Tickets, inventory, contracts, licenses: a GLPI server centralizes a lot of sensitive information. In other words, a vulnerable instance, especially if exposed to the Internet, is a prime target.

Sorry for the delay, but we need to talk about the two new GLPI releases published on September 16, 2026: GLPI 11.0.9 for the current branch, and GLPI 10.0.27 for organizations that have stayed on GLPI 10. Both releases are security updates.

At the end of June, I had already published an article about GLPI 11.0.8 and 10.0.26, which fixed 16 flaws including two critical ones. Less than three months later, here we go again. What do we know about these vulnerabilities? The answer is in the rest of this article.

Twelve Flaws in GLPI 11, Seven in GLPI 10

GLPI 11.0.9 fixes 12 vulnerabilities: 10 are rated important and 2 moderate. Among them, 7 security flaws also affect GLPI 10, and therefore components that have been around for some time, which matches exactly the content of version 10.0.27.

Let's start with the seven flaws common to both branches:

  • Unauthenticated SQL injection: it is located in the scheduling feature. This is the one to prioritize if your instance is exposed to the outside.
  • X509 authentication with an unverified certificate: GLPI could validate certificate-based X509 authentication even though the certificate had not been verified.
  • Race condition in the Marketplace: a specific condition that could allow the installation of a malicious plugin.
  • Malicious page upload: a booby-trapped file could be uploaded to the web server.
  • Arbitrary file deletion: this occurs during document creation.
  • Unexpected access to follow-ups, tasks, and solutions: this affects items generated from templates.
  • Access control : a user could make knowledge base articles, notes, or RSS feeds visible to people who should not have access to them

The five flaws specific to GLPI 11:

  • MFA bypass: a user who already has a GLPI account could bypass the multi-factor authentication protecting another user's account.
  • Four XSS flaws: one through importing a form illustration (the image representing a form in the GLPI 11 service catalog), and the other three are Stored XSS issues, affecting ticket authors, asset names, and network equipment templates.

Incidentally, I note that MFA in GLPI 11 has had a rough time: GLPI 11.0.6 in March, then GLPI 11.0.8 in June, each already fixed a flaw allowing multi-factor authentication bypass.

A Patch Every Two Weeks, the AI Effect

Beyond these vulnerabilities, there is an important detail mentioned in the announcement published on the GLPI blog. Teclib' warns that it will increase the frequency of its releases in the coming months to absorb the flood of security flaw reports. The reason, as you may have guessed? The rise of LLMs and agent-driven vulnerability research. "We have seen a significant increase in the volume of reports," the GLPI team acknowledges.

What Teclib' is observing with GLPI is not an isolated case; I would even say it is a global phenomenon across the entire open source ecosystem (which can also exhaust some project maintainers). Finally, there should be more news soon on the GLPI side, since GLPI 12 has reached Release Candidate status: the stable version is expected in October 2026.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.