Path traversal enables remote code execution in GLPI

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-48482?

CVE-2026-48482 is a vulnerability classified as Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), affecting glpi (affected versions: >= 11.0.0, < 11.0.8). This vulnerability is rated Critical, with a CVSS score of 9.4. Current sources do not report this vulnerability as exploited.

Overview

Original source data

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset directory. The imported file can be written to an executable server location, allowing a malicious script to be invoked remotely. This issue is fixed in version 11.0.8.

Affected products and scope

  • GLPI from glpi-project: the supplied affected facts identify >= 11.0.0, < 11.0.8.
  • GLPI 11.0.8 is confirmed by the record and the vendor advisory as patched.
  • The vendor advisory displays an affected range of >= 11.0.0; that broader notation does not independently establish the status of releases outside the bounded range in the normalized record. Do not infer the status of other release branches without separate evidence.

Technical details

The flaw is in the Form import flow, where GLPI processes an illustration or scene identifier to determine where an imported file is stored. An attacker-controlled identifier can escape the intended custom-asset directory through path traversal, allowing the imported file to be written to an executable server location.

The high-level attack flow established by the sources is:

  1. An account with form administrator privileges accesses Form import.
  2. The imported data contains a crafted illustration or scene identifier.
  3. The file is moved outside the intended custom-asset directory and may be placed in an executable location.
  4. A malicious script can then be invoked remotely.

The fix in FormSerializer::prepareIllustrationDataForImport adds validation that restricts illustration keys to the pattern [a-zA-Z0-9._-]+. IllustrationManager::saveCustomIllustration and IllustrationManager::saveCustomScene also verify that the resolved destination remains inside the corresponding directory before calling rename. The public sources do not fully establish the server process privileges or web-server configuration, so post-exploitation reach depends on the deployment environment.

Exploitability

The issue is reachable over the network through Form import and requires an account with form administrator privileges. The supplied record classifies the required privileges as high, the attack complexity as low, and user interaction as not required.

Successful exploitation may allow a malicious script to be installed on the GLPI server and executed remotely. The supplied record marks public exploit as false, but it does not establish whether exploitation has occurred in the wild.

Technical impact

A successful attack can cause GLPI to write an attacker-controlled file outside its intended storage directory and invoke a malicious script remotely. The technical result may be code execution in the application or web-server context, with possible effects on system confidentiality, integrity, and availability.

Impact to the operating system, other services, or data outside the GLPI process permissions is not established. The requirement for form administrator privileges is an important limitation of the attack path and makes review of those accounts a key defensive action.

Business impact

The flaw may allow a user with form administrator privileges to place a malicious script on the GLPI server and execute it remotely. Potential consequences include unauthorized modification of application code or data, access to information readable by the GLPI process, and service disruption.

Actual impact depends on the server process permissions, whether scripts are executable from the write location, and the isolation of the deployment. The available sources do not identify a specific incident, victim, or campaign.

Remediation

  1. Upgrade GLPI to 11.0.8, the patched version specified by the vendor advisory.
  2. While preparing the update, inventory servers running >= 11.0.0, < 11.0.8 and prioritize systems where untrusted or broadly assigned accounts can reach Form import.
  3. Review form administrator assignments and remove unnecessary privileges during the upgrade window.
  4. After updating, verify the deployed version and inspect recently created files in the custom-asset directory, scene directory, and executable locations.

The supplied advisory specifies upgrading to 11.0.8; it does not document a separate workaround.

Detection

  1. Inventory deployed GLPI versions and identify systems within the affected range stated in affected_summary.
  2. Identify deployments where form administrator accounts can use Form import.
  3. Review application and server logs for form-import activity, especially requests that create or process illustrations and scenes.
  4. Inspect the custom-asset directory, scene directory, and other locations where the web server can execute scripts for unexpected file creation or modification.
  5. Correlate newly created or modified files with Form import activity; this is a precautionary review, not a vendor-confirmed indicator.

The supplied sources do not define a product-specific log signature or IOC. Absence of matching log evidence does not prove that a system is safe.

Sources (15)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan