Skip to content

Latest commit

 

History

History
12 lines (8 loc) · 667 Bytes

File metadata and controls

12 lines (8 loc) · 667 Bytes

CVE-2026-46615 — glpi-agent

  • Advisory: GHSA-fcgf-g6c2-g838 · CVE-2026-46615
  • Severity: High · CWE-78
  • Status: publicly disclosed and fixed. Reported by Pig-Tail through coordinated disclosure.

Summary

Database inventory modules execute OS commands with unsanitized database names from MySQL and PostgreSQL servers

Write-up only. No standalone runnable PoC is published for this finding here — refer to the linked advisory for full technical detail, affected range, and the fixed version.