← Vulnerability feed

Vulnerability record · CVE-2023-46727 · published 13 December 2023

CVE-2023-46727: GLPI inventory endpoint SQL injection

Glpi Project · Glpi

GLPI versions 10.0.0 through 10.0.10 expose an inventory endpoint that is vulnerable to SQL injection. The flaw is remotely reachable without authentication and carries a critical CVSS score of 9.8, so unpatched instances are at serious risk.

9.8 CVSS 3.1 Critical EPSS 68% · top 0.7% CWE-89 · SQL injection
9.8CVSS 3.1 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory endpoint can be used to drive a SQL injection attack. Version 10.0.11 contains a patch for the issue. As a workaround, disable native inventory.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required and a very high EPSS percentile makes this an urgent patch target.

What it is

GLPI versions 10.0.0 through 10.0.10 expose an inventory endpoint that is vulnerable to SQL injection. The flaw is remotely reachable without authentication and carries a critical CVSS score of 9.8, so unpatched instances are at serious risk.

Impact

An unauthenticated attacker can inject SQL through the inventory endpoint, potentially reading or modifying database contents and compromising the GLPI application and its data.

Attack surface

The vulnerability is reached over the network via the GLPI inventory endpoint, per the CVSS vector AV:N/PR:N/UI:N, meaning no authentication or user interaction is required.

Exploitation

The record shows no CISA KEV listing and no public exploit references, but EPSS is 0.67726 (99.28th percentile), indicating a high predicted likelihood of exploitation activity.

What to do

  • Upgrade GLPI to version 10.0.11 or later, which contains the patch.
  • If immediate upgrade is not possible, disable native inventory as a workaround.
  • Restrict network access to the GLPI inventory endpoint to trusted inventory sources only.
  • Review database and application logs for anomalous queries against the inventory endpoint.

Detection

  • Monitor GLPI inventory endpoint requests for SQL metacharacters or unusual query patterns.
  • Alert on unexpected database errors or slow queries originating from the inventory endpoint.
  • Audit GLPI database accounts for signs of unauthorized reads or writes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-46727 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-35914GLPI htmlawed Test Script PHP Code InjectionThe htmLawed test script shipped inside GLPI up to 10.0.2 allows PHP code injection through the htmlawed module. Because the vulnerable file is reach…KEVEPSS 100%analysed9.8CVE-2026-26263Glpi-project glpi sql injection vulnerabilityGLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GL…EPSS 0.40%9.8CVE-2025-66417Glpi-project glpi sql injection vulnerabilityGLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inven…EPSS 0.48%9.8CVE-2025-24799GLPI unauthenticated SQL injection in inventory endpointGLPI, a free asset and IT management package, contains a SQL injection flaw reachable without authentication through its inventory endpoint. The issu…EPSS 87%analysed9.8CVE-2023-46726Glpi-project glpi injection vulnerabilityGLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server co…EPSS 1.3%9.8CVE-2023-42802Glpi-project glpi improper input validation vulnerabilityGLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation …EPSS 1.0%9.8CVE-2023-42461Glpi-project glpi sql injection vulnerabilityGLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…EPSS 1.1%9.8CVE-2023-41320Glpi-project glpi sql injection vulnerabilityGLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…EPSS 35%

Source: NIST National Vulnerability Database (record CVE-2023-46727), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.