GLPI 10 end of support: 10.0.28 is the last release

GLPI 10 end of support: 10.0.28 is the last release

On 30 September 2026 two GLPI versions shipped at once — 11.0.10 and 10.0.28. The 10.0.28 release note carries a sentence that matters more than the fixes themselves: with the upcoming release of GLPI 12.0.0, version 10.0.28 is the final release of the 10.0 branch, which will no longer receive bugfixes.

So the 10 branch does not end on a future date — it ends with a release you can already download. If you have deployed 10.0.28, you are running the most secure GLPI 10 that will ever exist.

What 10.0.28 still fixed

The 10.0.28 changelog lists six security entries — four High and two Medium:

  • authorization bypass in massive actions (High),
  • privilege escalation via user cloning (High),
  • improper rights checks in user deletion (High),
  • SQL injection through the form actors dropdown (High),
  • user name enumeration via the planning feature (Medium),
  • missing authorization checks in the planning feature (Medium).

The same wave on the 11 branch has eight entries — six High and two Medium. The two extra High issues are absent from the 10.0.28 notes. The first, 2FA deactivation or modification on accounts with higher privileges, cannot affect GLPI 10: two-factor authentication arrived in 11.0.0. For the second, a reflected XSS in the dashboard search result widget, the project does not say why it is missing from 10.0.28, even though that widget exists in GLPI 10 too. It is also the last time the comparison means anything: the next security release will have no 10.x column.

Skip 11.0.10

If you patched the 11 branch on 30 September, check the version number again. 11.0.10 shipped with a regression in the plugin system: a new check for colliding autoloaders prevented many plugins from being activated. The project responded on 1 October 2026 with 11.0.11, which fixes the regression and carries the same eight security fixes. Its own recommendation is to upgrade as soon as possible.

In practice: if you are on 11.0.10 and anything in your instance uses plugins, 11.0.11 is not optional. If you have not patched yet, install 11.0.11 directly.

Move to 11 now, or wait for 12

GLPI 12.0.0 is at Release Candidate stage — rc1 appeared on 3 September 2026, rc3 on 30 September 2026 — and is planned for October 2026; as of 5 October 2026 it had not shipped. Waiting and jumping straight from 10 to 12 is tempting — one migration instead of two.

Two things argue against it. Waiting means more weeks on a branch that will receive no fixes at all. And a fresh major version needs time before plugins, custom work and your integration layer catch up.

The lifecycle policy helps here. GLPI ships a major version once a year in October, and community support runs two years — eighteen months of bugfixes and security patches, then six months of security-only patches — with an extra year of extended support available on top. Version 11.0.0 was released on 1 October 2025, so under that policy it has bugfixes until roughly spring 2027 and security patches until roughly autumn 2027. Not a long horizon, but it is supported software today.

What to get done this week

  • Go through your instance list: which ones are still on 10.x, and do they have 10.0.28 applied.
  • Replace every 11.0.10 with 11.0.11.
  • Verify plugin compatibility against the 11 branch — usually the longest item on a migration plan.
  • Rehearse the database upgrade on a copy of production, not a clean test instance.
  • Record the 10.x end of support in your asset and risk register — an unmaintained system at the centre of ITSM is a finding in any security audit, and hard to defend under NIS2.

Migrating off GLPI 10 is weeks of work, not an evening. The good news is that the deadline is no longer unknown — it is now.

Need help with this topic?

Get in touch