CVE-2026-55214
HIGHCVSS 8.5/10
Last modified
CVE-2026-55214 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields.
Description
GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who opens the affected item's suppliers list triggers the stored cross-site scripting payload. This issue is fixed in version 11.0.8.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-55214?
GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who opens the affected item's suppliers list triggers the stored cross-site scripting payload. This issue is fixed in version 11.0.8.
How severe is CVE-2026-55214?
CVE-2026-55214 has a CVSS score of 8.5/10 (HIGH severity).
How do I fix CVE-2026-55214?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-55208Pimcore Studio Backend Bundle is the backend bundle for Pimc…7.7
- CVE-2026-55209resdata is software for reading and writing result files fro…9.8
- CVE-2026-55210Joplin is an open source note-taking and to-do application t…7.4
- CVE-2026-55211Surfio is a library for reading and writing surface files. P…9.8
- CVE-2026-55212Pimcore is an Open Source Data & Experience Management Platf…7.1
- CVE-2026-55213h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and …7.5
- CVE-2026-55215MariaDB Connector/Node.js is used to connect applications de…7.5
- CVE-2026-55217GLPI is a free asset and IT management software package. Fro…5.3
- CVE-2026-55219Paymenter is a free and open-source webshop solution for man…5.3
- CVE-2026-5522IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains…6.7
- CVE-2026-55220Pimcore is an Open Source Data & Experience Management Platf…9.3
- CVE-2026-55221Boruta is a standalone authorization server that aims to imp…6.5
Are you affected by CVE-2026-55214?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
