Sceawere
Vulnerability Detail
CVE-2026-108726UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
GLPI Unauthorized Map Search Access
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- glpi-project
- Product
- GLPI
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
GLPI through 12.0.0 contains a missing authorization vulnerability in ajax/map.php that allows authenticated low-privileged users to search itemtypes they cannot view by omitting the canView() check. Attackers can submit crafted itemtype and search criteria for types like Contact, Supplier, Contract and Budget to obtain match counts, titles and coordinates within their entities.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T13:17:16.277Z",
"pubdate": "2026-10-11T13:17:16.277Z",
"executiveSummary": "A missing authorization vulnerability exists in GLPI up to version 12.0.0, specifically within the ajax/map.php component. This security flaw enables authenticated users with low privileges to perform search queries against restricted itemtypes, bypassing necessary access control checks.\nThe vulnerability occurs because the application fails to invoke the canView() method, which is intended to enforce entity-based visibility and object-level permissions. Consequently, attackers can interact with sensitive modules—including Contact, Supplier, Contract, and Budget—without authorization.\nThe primary impact involves the unauthorized disclosure of information such as match counts, object titles, and geographical coordinates linked to specific entities. This data exposure poses significant privacy and operational risks, as low-privileged users can map out internal assets or business relationships that should remain hidden from their security context.\nExploitation requires an authenticated session within the GLPI environment but does not necessitate elevated administrative privileges, making it a persistent concern for multi-tenant or large-scale deployments where strictly enforced access control is mandatory.",
"technicalDetails": "The root cause of this vulnerability lies in an improper implementation of authorization logic within the ajax/map.php file of the GLPI framework. In GLPI's architectural design, administrative and inventory objects are typically gated by a 'canView()' function that validates whether the requesting user's session profile and assigned entity scope authorize them to interact with a specific resource type.\nIn the affected versions up to 12.0.0, the ajax/map.php endpoint processes user-supplied search parameters for mapping functionality without performing these critical permission validations. When an attacker sends a crafted request to this file, the application processes the query against restricted itemtypes regardless of the user's underlying permissions.\nThe exploitation flow is as follows: 1) The attacker initiates a request to the ajax/map.php endpoint. 2) The attacker provides input parameters specifying an itemtype for which they lack visibility, such as 'Supplier' or 'Budget'. 3) Due to the missing canView() call, the underlying database search logic executes the query using the application's global privilege context rather than the session-restricted context. 4) The server returns JSON or similar structured responses containing the titles, counts, and coordinate data mapped to the requested objects.\nBecause the server fails to verify if the requesting user belongs to the entity associated with the target records, the system effectively acts as an information oracle. An attacker can iterate through various itemtype identifiers and search criteria to harvest metadata, facilitating reconnaissance against the organization's supply chain, budgetary allocations, or contract details.\nThis vulnerability is particularly impactful in environments where segregation of duties is expected between departments, as a low-privileged user can enumerate information concerning sensitive entity objects across the entire GLPI instance. The lack of input sanitization and authorization enforcement at the controller level allows for a broad bypass of the intended security model, exposing geographic coordinates and organizational business intelligence that is otherwise protected by the GLPI access control system."
}