CVE-2026-23489 is an improper input validation vulnerability in the Fields plugin for GLPI, which provides custom fields for GLPI item forms. In versions prior to 1.23.3, a user authorized to create dropdowns can cause arbitrary PHP code to be executed. The issue is fixed in Fields version 1.23.3.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact proof-of-concept exploit for CVE-2026-23489 affecting the GLPI Fields plugin <= 1.23.2. It contains two files: a README with usage instructions and one Python exploit script, poc_fields_rce.py, which is the sole entry point. The script is not part of a larger exploit framework. The exploit performs authenticated blind RCE against a GLPI web application by abusing how the Fields plugin generates PHP classes for dropdown custom fields. Specifically, it creates a new container, then creates a dropdown field whose label is crafted to break out of the expected PHP structure and inject attacker-controlled PHP code. The injected code is supplied directly by the operator through the --php argument. Because the payload executes at file scope in generated PHP, the result is arbitrary PHP execution as the web server user. Operational flow: the script seeds a cookie jar with a user-provided GLPI session cookie, verifies authentication by requesting /front/central.php, retrieves CSRF tokens from plugin pages, creates a Fields container, creates the malicious dropdown field via /plugins/fields/front/field.form.php, and optionally purges the container afterward to remove traces and avoid breaking the GLPI dropdown UI. The exploit is described as blind, so success is inferred from side effects rather than direct command output. Notable capabilities include authenticated session validation, CSRF token extraction, malicious object creation through legitimate application workflows, arbitrary PHP execution, and optional cleanup. The payload is customizable but basic, making this more than a pure PoC yet not framework-weaponized. The repository does not include persistence, lateral movement, or automated post-exploitation beyond optional cleanup.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.