VulnSea

snipe-it vulnerabilities

CVEs whose affected-version data names the snipe-it package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

50 CVEsRSS

CVE-2026-86774Medium· 6.3
2w ago

Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload and delete file attachments on Asset …

Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload and delete file attachments on Asset …

▾ Sunlitsnipeitapp · snipe-itEPSS 0.17%via NVD
CVE-2026-86752Medium· 5.4
2w ago

snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks

snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and assets.audit permi…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.18%via NVD
CVE-2026-86762High· 8.1
2w ago

Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php, and deactivating a user does not revoke that user's Passport personal access tokens

Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php, and deactivating a user does not revoke that user's Passport personal access tokens. As a result, although a d…

▾ Twilightsnipeitapp · snipe-itEPSS 0.32%via NVD
CVE-2026-86764Medium· 6.5
2w ago

Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components

Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only assets.view on the parent asset befor…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.21%via NVD
CVE-2026-86759High· 7.1
2w ago

Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs

Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies…

▾ Twilightsnipeitapp · snipe-itEPSS 0.21%via NVD
CVE-2026-86753Medium· 4.3
2w ago

snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint

snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint. Authenticated users can bypass administrative restrictions and create checkout requests fo…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.20%via NVD
CVE-2026-86749Medium· 6.3
2w ago

Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of storage write operations in ImageUploadRequest::handleImages()

Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of storage write operations in ImageUploadRequest::handleImages(). Because Laravel's default disk mode does not throw on failure, a silently failed Storage::disk('…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.23%via NVD
CVE-2026-86748Medium· 6.1PoC
2w ago

Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint

Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery path or rollback mec…

▾ Twilightsnipeitapp · snipe-itEPSS 0.31%via NVD
CVE-2026-86738High· 8.7
2w ago

Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters

Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS paylo…

▾ Twilightsnipeitapp · snipe-itEPSS 0.27%via NVD
CVE-2026-86737Medium· 4.3
2w ago

snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint

snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and enumerate asset tags across tenants, including …

▾ Sunlitsnipeitapp · snipe-itEPSS 0.17%via NVD
CVE-2026-86736Medium· 4.3
2w ago

snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requ…

snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requ…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.18%via NVD
CVE-2026-86735Medium· 5.0
2w ago

snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets

snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets. Attackers with super-admin privileges can…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.24%via NVD
CVE-2026-86734Medium· 6.5
2w ago

Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{acceptance} endpoint, allowing authenticated users to submit unbounded input that reaches synchronous CommonMark rendering

Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{acceptance} endpoint, allowing authenticated users to submit unbounded input that reaches synchronous CommonMark rendering. Attackers can s…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.30%via NVD
CVE-2026-86733High· 7.2
2w ago

Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets lines beginning with backslash commands su…

Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets lines beginning with backslash commands su…

▾ Twilightsnipeitapp · snipe-itEPSS 0.33%via NVD
CVE-2026-85617High· 8.8
3w ago

snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside their authorized scope

snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside their authorized scope. Attackers can include unauthorized user IDs i…

▾ Twilightsnipeitapp · snipe-itEPSS 0.26%via NVD
CVE-2026-85616High· 8.5
3w ago

Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled

Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission can enumerate sequential a…

▾ Twilightsnipeitapp · snipe-itEPSS 0.25%via NVD
CVE-2026-19579Medium· 5.4
1mo ago

Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint

Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments …

▾ Sunlitsnipeitapp · snipe-itEPSS 0.28%via NVD
CVE-2026-55478Medium· 5.4
2mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but does not authorize access to the referenced license object, allowing a low-privilege user …

▾ Sunlitsnipeitapp · snipe-itEPSS 0.18%via NVD
CVE-2026-55474Medium· 6.5
2mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.33%via NVD
CVE-2026-44832High· 8.8
4mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]…

▾ Twilightsnipeitapp · snipe-itEPSS 0.32%via NVD
snipe-it vulnerabilities (CVEs) — page 2 · VulnSea