How We Found CVE-2026-42318 in GLPI
A CVE we recently published. An authorization bypass in GLPI let a technician-level user delete any object in the instance — how we found it, why scanners miss this class of bug, and how disclosure played out.
Read More