CVE-2026-86738
- EPSS 0.28%
- Veröffentlicht 08.09.2026 15:14:06
- Zuletzt bearbeitet 09.09.2026 13:06:27
Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using @im...
CVE-2026-86736
- EPSS 0.18%
- Veröffentlicht 08.09.2026 15:14:05
- Zuletzt bearbeitet 19.09.2026 15:17:07
snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attacke...
CVE-2026-86737
- EPSS 0.17%
- Veröffentlicht 08.09.2026 15:14:05
- Zuletzt bearbeitet 10.09.2026 14:17:10
snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and enumerate asset tags across tenants, including soft-deleted ...
- EPSS 0.24%
- Veröffentlicht 08.09.2026 15:14:04
- Zuletzt bearbeitet 09.09.2026 13:45:44
snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets. Attackers with super-admin privileges can configure we...
CVE-2026-86733
- EPSS 0.33%
- Veröffentlicht 08.09.2026 15:14:03
- Zuletzt bearbeitet 09.09.2026 13:57:28
Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets lines beginning with backslash commands such as `\!` as...
CVE-2026-86734
- EPSS 0.3%
- Veröffentlicht 08.09.2026 15:14:03
- Zuletzt bearbeitet 10.09.2026 16:18:04
Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{acceptance} endpoint, allowing authenticated users to submit unbounded input that reaches synchronous CommonMark rendering. Attackers can submit large n...
CVE-2026-85617
- EPSS 0.26%
- Veröffentlicht 04.09.2026 11:30:11
- Zuletzt bearbeitet 16.09.2026 20:41:58
snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside their authorized scope. Attackers can include unauthorized user IDs in bulk delete...
CVE-2026-85616
- EPSS 0.27%
- Veröffentlicht 04.09.2026 11:30:10
- Zuletzt bearbeitet 16.09.2026 20:42:07
Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission can enumerate sequential acceptance IDs...
CVE-2026-84206
- EPSS 0.22%
- Veröffentlicht 01.09.2026 15:19:00
- Zuletzt bearbeitet 29.09.2026 19:00:51
Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. Attackers with edit permissions can post asset identifiers to the...
CVE-2026-55694
- EPSS 0.24%
- Veröffentlicht 19.08.2026 18:28:22
- Zuletzt bearbeitet 30.09.2026 12:58:30
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /api/v1/users/{target_id}/eulas to obtain another user's randomized EULA filename and then download the signed file through /account/stored-eula-file/{fi...