External risk intelligence

GLPI Form Import Directory Traversal Leading to Remote Script Invocation

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-48482

GLPI is an IT asset management platform frequently deployed as a web-based application reachable over a network. While this specific vulnerability requires administrator privileges, the application itself is commonly hosted as a web service, making the interface reachable via the internet in many standard enterprise deployment patterns.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability in GLPI IT management software allows a malicious actor with administrator privileges to upload a crafted file, potentially leading to the remote execution of scripts on the server. The primary concern is to confirm if your organization utilizes this software and if it is exposed to unauthorized access.

  • Admins can run malicious code.
  • Confirm if GLPI is in use.
  • Assess potential exposure and risk.

Attack Path

How an attacker could exploit the issue

An attacker with administrator privileges could exploit this vulnerability by crafting a malicious file containing an illustration or scene identifier. When this file is imported using the Form import feature, it can write an executable file to a server location outside the designated directory. This allows an attacker to remotely execute malicious scripts on the server.

  • Requires administrator access.
  • Exploited through crafted file import.
  • Risk of remote script execution.

Live Threat

Current exploitation, exposure, and threat context

A form administrator could upload a malicious illustration or scene identifier that, when imported, is written to an executable server location. This could allow an attacker to remotely execute malicious scripts on the server.

  • Server-side scripts could be executed.
  • Malicious files could be uploaded to the server.
  • Remote code execution on the server.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for IT asset management, application ownership, and infrastructure hosting should coordinate to address this vulnerability. The initial focus should be on discovering all instances of the affected software, verifying their exposure and business criticality, and identifying the specific application owner for each deployment. This will enable a prioritized remediation plan to mitigate risk.

  • Own Issue: IT Asset Management and Application Owners.
  • Verify First: Identify all GLPI instances and exposure.
  • Action Follows: Plan and coordinate targeted remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is GLPI software?

GLPI is an open-source IT service management and asset tracking platform. Organizations use it to manage their technical infrastructure, inventory, and support tickets through a centralized web interface. It acts as a backbone for internal service desk operations and hardware lifecycle tracking.

How does CVE-2026-48482 work?

This vulnerability is classified as Path Traversal (CWE-22). It occurs when the software fails to properly restrict file paths during a form import process. By manipulating an illustration or scene identifier, an authorized user can trick the system into saving a file into an executable directory on the server, rather than the intended safe folder.

Do I need to worry about non-administrator users triggering this?

No. The vulnerability specifically requires the attacker to hold form administrator privileges within the application. Actions performed by standard users or unauthenticated visitors do not possess the necessary authorization level to access or manipulate the specific import feature required to trigger this file path traversal.

Is my instance at risk if it is internal only?

Halo Surface Signal indicates that GLPI is frequently deployed as a web-based service. While the risk is higher for internet-facing instances where an attacker could gain remote access to the admin panel, internal instances remain a concern if a user account is compromised or if there is a malicious insider, as the flaw exists within the application's core logic.

When should I update my GLPI installation?

You should prioritize updating to version 11.0.8 immediately. Since this flaw allows for the creation and execution of scripts on your server, your first steps should be to identify all deployed instances, confirm their current versions, and coordinate with your infrastructure team to apply the provided patch to prevent unauthorized code execution.

References