snipe has 20 CVEs on record. Disclosure cadence is accelerating: 15 in the last 90 days against 5 in the 90 before. The busiest recent month was August 2026 with 15. The median CVSS is 6.1 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-862 (7) and CWE-863 (6).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.1
- Publish → KEV
- —
- Last 90 days
- 15 prev 5
Worst active — by depth score
CVE-2026-54329High· 8.5Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection47CVE-2026-55516High· 7.7Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update42CVE-2026-55694HighSnipe-IT is an IT asset/license management system41CVE-2026-55460High· 7.1Snipe-IT has an authorization bypass on bulk editing users39CVE-2026-48507High· 7.1Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users39
snipe vulnerabilities
CVEs affecting snipe, newest first. Open any entry for full detail, references, and exploit status.
20 CVEsRSS
CVE-2026-55843High· 6.5Snipe-IT has an Improper Privilege Management issue
Snipe-IT has an Improper Privilege Management issue
CVE-2026-55460High· 7.1Snipe-IT has an authorization bypass on bulk editing users
Snipe-IT has an authorization bypass on bulk editing users
CVE-2026-55464Medium· 5.4Snipe-IT vulnerable to stored XSS via Markdown custom field
Snipe-IT vulnerable to stored XSS via Markdown custom field
CVE-2026-55472Medium· 4.3Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
CVE-2026-55476MediumSnipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter
Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter
CVE-2026-55516High· 7.7Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update
Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update
CVE-2026-55694HighSnipe-IT is an IT asset/license management system
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /api/v1/users/{target_id}/eulas to obtain another user's randomized EULA filename and then download the signed file through /account/stored-…
CVE-2026-55703Medium· 4.3Snipe-IT is an IT asset/license management system
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same company without asset or maintenance permission. app/Http/Control…
CVE-2026-61807MediumSnipe-IT is an IT asset/license management system
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the table component $name becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-si…
CVE-2026-49870Medium· 5.9Snipe-IT is an IT asset/license management system
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or attempt counter, allowing an attacker with valid credentials to submit unlimited TOTP guesses against the three accepte…
CVE-2026-49976Medium· 6.5Snipe-IT is an IT asset/license management system
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update mode to overwrite the email address of a non-admin user and then request a password reset to take over that account. …
CVE-2026-50550Medium· 5.8Snipe-IT is an IT asset/license management system
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmin's two-factor authentication through app/Http/Controllers/Api/UsersController.php postTwoFactorReset(). The endpoint…
CVE-2026-55482Medium· 6.3Snipe-IT is an IT asset/license management system
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/BulkAssetsController.php update() to submit company_id directly without Company::getIdForCurrentUser(), allowing asse…
CVE-2026-55483MediumSnipe-IT is an IT asset/license management system
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission can submit the admin permission while creating a user because store() in app/Http/Controllers/Users/UsersController.php…
CVE-2026-55519Medium· 5.4Snipe-IT is an IT asset/license management system
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside the user's ownership or company assignment. The destroy() methods in …
CVE-2026-48492MediumSnipe-IT's selectlist visibility is too permissive
Snipe-IT's selectlist visibility is too permissive
CVE-2026-48493Medium· 5.5Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
CVE-2026-48507High· 7.1Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
CVE-2026-55542LowSnipe-IT's S3 signature image retrieval lacks authorization before temporary URL
Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL
CVE-2026-54329High· 8.5Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection
Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection