CVE-2025-23046 - CVE House
Back to Database
Status published Medium CVE-2025-23046

GLPI vulnerable to unauthorized authentication by email using the OAuthIMAP plugin

Vulnerability Description

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.18, if a "Mail servers" authentication provider is configured to use an Oauth connection provided by the OauthIMAP plugin, anyone can connect to GLPI using a user name on which an Oauth authorization has already been established. Version 10.0.18 contains a patch. As a workaround, one may disable any "Mail servers" authentication provider configured to use an Oauth connection provided by the OauthIMAP plugin.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-23046

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

glpi-project

View all reports →

Affected Software

glpi
Vulnerable Versions:
>= 9.5.0, < 10.0.18

Timeline

Official Publish: February 25th, 2025
Last Modified: February 25th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.