{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-11T16:20:33.532","vulnerabilities":[{"cve":{"id":"CVE-2026-26001","sourceIdentifier":"security-advisories@github.com","published":"2026-03-18T00:16:18.770","lastModified":"2026-03-23T18:14:43.043","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, non sanitized user input can lend to an SQL injection from reports, with adequate rights. This vulnerability is fixed in 1.6.6."},{"lang":"es","value":"El plugin de inventario de GLPI gestiona el descubrimiento de red, el inventario, el despliegue de software y la recopilación de datos para los agentes de GLPI. Antes de la versión 1.6.6, la entrada de usuario sin sanear podía dar lugar a una inyección SQL desde informes, con permisos adecuados. Esta vulnerabilidad está corregida en la versión 1.6.6."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:glpi-project:glpi_inventory:*:*:*:*:*:*:*:*","versionEndExcluding":"1.6.6","matchCriteriaId":"98C6C195-DCBB-4921-BDFF-CAD1971700EA"}]}]}],"references":[{"url":"https://github.com/glpi-project/glpi-inventory-plugin/security/advisories/GHSA-gp4r-m42c-wvgx","source":"security-advisories@github.com","tags":["Vendor Advisory"]}]}}]}