{"api_version":"1","generated_at":"2026-07-24T00:19:34+00:00","cve":"CVE-2021-21326","urls":{"html":"https://cve.report/CVE-2021-21326","api":"https://cve.report/api/cve/CVE-2021-21326.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-21326","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-21326"},"summary":{"title":"CVE-2021-21326","description":"GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 it is possible to create tickets for another user with self-service interface without delegatee systems enabled. This is fixed in version 9.5.4.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2021-03-08 17:15:00","updated_at":"2021-03-16 21:01:00"},"problem_types":["CWE-862"],"metrics":[],"references":[{"url":"https://github.com/glpi-project/glpi/security/advisories/GHSA-vmj9-cg56-p7wh","name":"https://github.com/glpi-project/glpi/security/advisories/GHSA-vmj9-cg56-p7wh","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"Horizontal Privilege Escalation · Advisory · glpi-project/glpi · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://github.com/glpi-project/glpi/releases/tag/9.5.4","name":"https://github.com/glpi-project/glpi/releases/tag/9.5.4","refsource":"MISC","tags":["Release Notes","Third Party Advisory"],"title":"Release 9.5.4 · glpi-project/glpi · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-21326","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-21326","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"21326","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"glpi-project","cpe5":"glpi","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2021-21326","STATE":"PUBLIC","TITLE":"Horizontal Privilege Escalation"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"glpi","version":{"version_data":[{"version_value":"< 9.5.4"}]}}]},"vendor_name":"glpi-project"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 it is possible to create tickets for another user with self-service interface without delegatee systems enabled. This is fixed in version 9.5.4."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-862 Missing Authorization"}]}]},"references":{"reference_data":[{"name":"https://github.com/glpi-project/glpi/releases/tag/9.5.4","refsource":"MISC","url":"https://github.com/glpi-project/glpi/releases/tag/9.5.4"},{"name":"https://github.com/glpi-project/glpi/security/advisories/GHSA-vmj9-cg56-p7wh","refsource":"CONFIRM","url":"https://github.com/glpi-project/glpi/security/advisories/GHSA-vmj9-cg56-p7wh"}]},"source":{"advisory":"GHSA-vmj9-cg56-p7wh","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2021-03-08 17:15:00","lastModifiedDate":"2021-03-16 21:01:00","problem_types":["CWE-862"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*","versionEndExcluding":"9.5.4","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"21326","Ordinal":"195452","Title":"CVE-2021-21326","CVE":"CVE-2021-21326","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"21326","Ordinal":"1","NoteData":"GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 it is possible to create tickets for another user with self-service interface without delegatee systems enabled. This is fixed in version 9.5.4.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"21326","Ordinal":"2","NoteData":"2021-03-08","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"21326","Ordinal":"3","NoteData":"2021-03-08","Type":"Other","Title":"Modified"}]}}}