{"id":"CVE-2026-86735","title":"snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets","summary":"snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets. Attackers with super-admin privileges can…","severity":"medium","cvss":5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N","cwe":["CWE-918"],"vendor":"snipeitapp","product":"snipe-it","affected":["snipe-it < 8.7.0"],"patched":["snipe-it 8.7.0"],"published":"2026-09-08","updated":"2026-09-09","sourceUpdated":"2026-09-09T13:45:44.263","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86735","references":[{"url":"https://github.com/grokability/snipe-it/security/advisories/GHSA-5j6m-rr83-rpj7","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-ssrf-via-ipv6-transition-address-bypass","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-08T15:37:37.059741Z"},"ingestedAt":"2026-09-08T15:33:26.987Z","epss":0.0024,"epssPercentile":0.15414,"slug":"CVE-2026-86735","body":"## Overview\n\nsnipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets. Attackers with super-admin privileges can configure webhook URLs using NAT64, 6to4, or Teredo transition addresses to bypass SSRF guards and access internal services or cloud metadata endpoints.\n\n## Affected\n\n- `snipe-it < 8.7.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `snipe-it 8.7.0`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}