CVE-2026-23489
CVE-2026-23489 is a critical-severity vulnerability in Teclib-edition Fields with a CVSS 3.x base score of 9.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-20.
Key facts
- Severity: Critical (CVSS 3.x base score 9.1)
- EPSS exploit prediction: 0% (21st percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-12456
- Weakness: CWE-20
- Affected product: Teclib-edition Fields
- Published:
- Last modified:
Description
Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdowns. This issue has been patched in version 1.23.3.
Frequently asked questions
- What is CVE-2026-23489?
- Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdowns. This issue has been patched in version 1.23.3.
- How severe is CVE-2026-23489?
- CVE-2026-23489 has a CVSS 3.x base score of 9.1, rated critical severity. It is exploitable over network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-23489 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (21st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-23489?
- CVE-2026-23489 affects Teclib-edition Fields. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-23489?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- Does CVE-2026-23489 have an EU (EUVD) identifier?
- Yes. CVE-2026-23489 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-12456.
- When was CVE-2026-23489 published?
- CVE-2026-23489 was published on 2026-03-16 and last updated on 2026-06-17.
References
- https://github.com/pluginsGLPI/fields/releases/tag/1.23.3
- https://github.com/pluginsGLPI/fields/security/advisories/GHSA-rj7q-mmx9-fhq7
Affected products (1)
- cpe:2.3:a:teclib-edition:fields:*:*:*:*:*:glpi:*:*
More vulnerabilities in Teclib-edition Fields
- CVE-2019-12723 — Critical (CVSS 9.8): An issue was discovered in the Teclib Fields plugin through 1.9.2 for GLPI. it allows SQL Injection via container_id…
- CVE-2023-28855 — Medium (CVSS 6.5): Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to versions 1.13.1 and…
All CVEs affecting Teclib-edition Fields →
Other CWE-20 (Improper Input Validation) vulnerabilities
- CVE-2026-93952 — Critical (CVSS 10.0): VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access…
- CVE-2026-77554 — Critical (CVSS 10.0): A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi…
- CVE-2026-77537 — Critical (CVSS 10.0): A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi…
- CVE-2026-48056 — Critical (CVSS 10.0): Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0…
- CVE-2026-33267 — Critical (CVSS 10.0): Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0…
- CVE-2026-47668 — Critical (CVSS 10.0): DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST…
Browse all CWE-20 (Improper Input Validation) vulnerabilities →