CVE-2026-49470

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not limit failed submissions per user. An attacker who has obtained a user's primary authentication credentials can repeatedly submit TOTP values against the MFA verification flow, making brute-force compromise of the second factor and subsequent account takeover possible. This issue is fixed in version 11.0.8.

  • Published Sep 25, 2026
  • CVSS 7.7 high
  • 0.4% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-49470 at the National Vulnerability Database