#VU124955 Improper Neutralization of Special Elements Used in a Template Engine in GLPI - CVE-2026-26026
Published: April 6, 2026
GLPI
glpi-project
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements used in a template engine in the template engine when processing administrator-controlled template input. A remote privileged user can inject crafted template expressions to execute arbitrary code.
High privileges are required.