Vulnerability Details CVE-2026-22247
GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through the Webhook feature. This issue has been patched in version 11.0.5.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 5.6%
CVSS Severity
CVSS v3 Score 4.1
Products affected by CVE-2026-22247
-
cpe:2.3:a:glpi-project:glpi:11.0.0
-
cpe:2.3:a:glpi-project:glpi:11.0.1
-
cpe:2.3:a:glpi-project:glpi:11.0.2
-
cpe:2.3:a:glpi-project:glpi:11.0.3
-
cpe:2.3:a:glpi-project:glpi:11.0.4