This is a security release, upgrading is recommended
You will find below the list of security issues fixed in this bugfixes version:
- [SECURITY - MODERATE] Session stealing on externally authenticated user change (CVE-2026-23624)
- [SECURITY - HIGH] Remote Code Execution via malicious upload (CVE-2026-22248)
- [SECURITY - MODERATE] SSRF via Webhooks (CVE-2026-22247)
The full changelog is available for more details.
We would like to thank all people who contributed to this new version and all those who contributes regularly to the GLPI project!
Regards.