{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T00:09:01.892","vulnerabilities":[{"cve":{"id":"CVE-2026-23624","sourceIdentifier":"security-advisories@github.com","published":"2026-02-04T18:16:08.913","lastModified":"2026-06-17T10:21:51.523","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.0.5, when remote authentication is used, based on SSO variables, a user can steal a GLPI session previously opened by another user on the same machine. This issue has been patched in versions ."},{"lang":"es","value":"GLPI es un paquete de software gratuito de gestión de activos y TI. En versiones desde la 0.71 hasta antes de la 10.0.23 y antes de la 11.0.5, cuando se utiliza la autenticación remota, basada en variables SSO, un usuario puede robar una sesión GLPI previamente abierta por otro usuario en la misma máquina. Este problema ha sido parcheado en las versiones ."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"glpi-project","product":"glpi","versions":[{"version":">= 0.71, < 10.0.23","status":"affected"},{"version":">= 11.0.0-alpha, < 11.0.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-04T19:56:08.999117Z","id":"CVE-2026-23624","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-384"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*","versionStartIncluding":"0.71","versionEndExcluding":"10.0.23","matchCriteriaId":"D09C27B0-C82A-4F14-845D-FF7991EDBBE4"},{"vulnerable":true,"criteria":"cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.0.5","matchCriteriaId":"C13BB849-4C19-473A-B105-57915EE59C49"}]}]}],"references":[{"url":"https://github.com/glpi-project/glpi/releases/tag/10.0.23","source":"security-advisories@github.com","tags":["Product","Release Notes"]},{"url":"https://github.com/glpi-project/glpi/releases/tag/11.0.5","source":"security-advisories@github.com","tags":["Product","Release Notes"]},{"url":"https://github.com/glpi-project/glpi/security/advisories/GHSA-5j4j-vx46-r477","source":"security-advisories@github.com","tags":["Vendor Advisory"]}]}}]}