Sceawere

Vulnerability Detail

CVE-2026-108726UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GLPI Unauthorized Map Search Access

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
4h ago
Vendor
glpi-project
Product
GLPI
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

GLPI through 12.0.0 contains a missing authorization vulnerability in ajax/map.php that allows authenticated low-privileged users to search itemtypes they cannot view by omitting the canView() check. Attackers can submit crafted itemtype and search criteria for types like Contact, Supplier, Contract and Budget to obtain match counts, titles and coordinates within their entities.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T13:17:16.277Z",
  "pubdate": "2026-10-11T13:17:16.277Z",
  "executiveSummary": "A missing authorization vulnerability exists in GLPI up to version 12.0.0, specifically within the ajax/map.php component. This security flaw enables authenticated users with low privileges to perform search queries against restricted itemtypes, bypassing necessary access control checks.\nThe vulnerability occurs because the application fails to invoke the canView() method, which is intended to enforce entity-based visibility and object-level permissions. Consequently, attackers can interact with sensitive modules—including Contact, Supplier, Contract, and Budget—without authorization.\nThe primary impact involves the unauthorized disclosure of information such as match counts, object titles, and geographical coordinates linked to specific entities. This data exposure poses significant privacy and operational risks, as low-privileged users can map out internal assets or business relationships that should remain hidden from their security context.\nExploitation requires an authenticated session within the GLPI environment but does not necessitate elevated administrative privileges, making it a persistent concern for multi-tenant or large-scale deployments where strictly enforced access control is mandatory.",
  "technicalDetails": "The root cause of this vulnerability lies in an improper implementation of authorization logic within the ajax/map.php file of the GLPI framework. In GLPI's architectural design, administrative and inventory objects are typically gated by a 'canView()' function that validates whether the requesting user's session profile and assigned entity scope authorize them to interact with a specific resource type.\nIn the affected versions up to 12.0.0, the ajax/map.php endpoint processes user-supplied search parameters for mapping functionality without performing these critical permission validations. When an attacker sends a crafted request to this file, the application processes the query against restricted itemtypes regardless of the user's underlying permissions.\nThe exploitation flow is as follows: 1) The attacker initiates a request to the ajax/map.php endpoint. 2) The attacker provides input parameters specifying an itemtype for which they lack visibility, such as 'Supplier' or 'Budget'. 3) Due to the missing canView() call, the underlying database search logic executes the query using the application's global privilege context rather than the session-restricted context. 4) The server returns JSON or similar structured responses containing the titles, counts, and coordinate data mapped to the requested objects.\nBecause the server fails to verify if the requesting user belongs to the entity associated with the target records, the system effectively acts as an information oracle. An attacker can iterate through various itemtype identifiers and search criteria to harvest metadata, facilitating reconnaissance against the organization's supply chain, budgetary allocations, or contract details.\nThis vulnerability is particularly impactful in environments where segregation of duties is expected between departments, as a low-privileged user can enumerate information concerning sensitive entity objects across the entire GLPI instance. The lack of input sanitization and authorization enforcement at the controller level allows for a broad bypass of the intended security model, exposing geographic coordinates and organizational business intelligence that is otherwise protected by the GLPI access control system."
}
CVE-2026-108726: GLPI Unauthorized Map Search Access (MEDIUM Severity, CVSS: 4.3) | Sceawere