VulnSea

snipeitapp has 48 CVEs on record. Disclosure cadence is accelerating: 47 in the last 90 days against 1 in the 90 before. The busiest recent month was September 2026 with 44. The median CVSS is 6.3 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (9) and CWE-639 (7).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.3
Publish → KEV
Last 90 days
47 prev 1

Products

  • snipe-it 48
48
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

snipeitapp vulnerabilities

CVEs affecting snipeitapp, newest first. Open any entry for full detail, references, and exploit status.

48 CVEsRSS

CVE-2026-86770High· 8.1PoC
1w ago

Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case variants of victim usernames

Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case variants of victim usernames. Attackers c…

Midnightsnipeitapp · snipe-itEPSS 0.32%via NVD
CVE-2026-86765Medium· 6.5PoC
1w ago

Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset update endpoint

Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset update endpoint. Authenticated users with edit permission but explicitly denied checkout permission can reassign asse…

Twilightsnipeitapp · snipe-itEPSS 0.23%via NVD
CVE-2026-86760Medium· 5.4PoC
1w ago

Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/Users/UsersController::update()

Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/Users/UsersController::update(). The single-user edit route assigned the activated field from the request payload befo…

Twilightsnipeitapp · snipe-itEPSS 0.22%via NVD
CVE-2026-86755Medium· 5.4
1w ago

Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middleware, without the self.api permission ga…

Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middleware, without the self.api permission ga…

Sunlitsnipeitapp · snipe-itEPSS 0.20%via NVD
CVE-2026-86750High· 7.7
1w ago

Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment authorization before persisting user records via the REST API

Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment authorization before persisting user records via the REST API. In Api\UsersController::store() and ::update(), the user record is filled from the request and …

Twilightsnipeitapp · snipe-itEPSS 0.19%via NVD
CVE-2026-86745Medium· 6.5
1w ago

Snipe-IT is an IT asset management application

Snipe-IT is an IT asset management application. In Snipe-IT master-branch builds after 8.6.3 (the code was never included in a tagged release), SettingsController::downloadLocationScopingReport streams the FMCS location-scoping mismatch …

Sunlitsnipeitapp · snipe-itEPSS 0.45%via NVD
CVE-2026-86740Low· 3.8
1w ago

Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk

Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk. Admini…

Sunlitsnipeitapp · snipe-itEPSS 0.21%via NVD
CVE-2026-86773Medium· 5.4PoC
1w ago

Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updateAccessory, and updateModel endpoints and in the storeModel endpoint for Predefined Kits

Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updateAccessory, and updateModel endpoints and in the storeModel endpoint for Predefined Kits. The existing check authoriz…

Twilightsnipeitapp · snipe-itEPSS 0.17%via NVD
CVE-2026-86758Medium· 6.5
1w ago

Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys

Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys. Attackers can download all lic…

Sunlitsnipeitapp · snipe-itEPSS 0.24%via NVD
CVE-2026-86744Low· 2.2
1w ago

Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) contain a race condition in the asset checkout paths

Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) contain a race condition in the asset checkout paths. Api\AssetsController::checkout() and Assets\AssetCheckoutController::store() call Asset::availableForChec…

Sunlitsnipeitapp · snipe-itEPSS 0.21%via NVD
CVE-2026-86763Low· 3.5
1w ago

Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewire\Importer, mounted at the imports.index route)

Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewire\Importer, mounted at the imports.index route). The component only checked the broad 'import' ability at mount time,…

Sunlitsnipeitapp · snipe-itEPSS 0.16%via NVD
CVE-2026-86757Medium· 6.5
1w ago

Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field values in asset form templates for listbox, textarea, markdown-textarea, and date/datetime picker elements

Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field values in asset form templates for listbox, textarea, markdown-textarea, and date/datetime picker elements. Authenticated users with assets.edit, assets.checki…

Sunlitsnipeitapp · snipe-itEPSS 0.22%via NVD
CVE-2026-86743Medium· 5.0PoC
1w ago

Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies

Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the unaccepted_assets repo…

Twilightsnipeitapp · snipe-itEPSS 0.25%via NVD
CVE-2026-86768Medium· 5.4PoC
1w ago

Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets

Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets. Attackers can submit POST requests to hardware, compo…

Twilightsnipeitapp · snipe-itEPSS 0.23%via NVD
CVE-2026-86747Medium· 5.4
1w ago

Snipe-IT is an open source IT asset management system

Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endpoints POST /reports/unaccepted_assets/sent_reminder (ReportsController::sentAssetAcceptanceReminder) and DELETE /repo…

Sunlitsnipeitapp · snipe-itEPSS 0.18%via NVD
CVE-2026-86739Low· 3.1
1w ago

Snipe-IT 8.6.3 and earlier do not check the return value of Storage::put() when writing the signature PNG and the generated acceptance PDF in Account\AcceptanceController::store()

Snipe-IT 8.6.3 and earlier do not check the return value of Storage::put() when writing the signature PNG and the generated acceptance PDF in Account\AcceptanceController::store(). On filesystem drivers that return false instead of throw…

Sunlitsnipeitapp · snipe-itEPSS 0.25%via NVD
CVE-2026-86742Medium· 6.5
1w ago

Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export

Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export. ReportsController::postAssetAcceptanceReport builds the CSV by hand (stripping commas and joining rows manually) and, un…

Sunlitsnipeitapp · snipe-itEPSS 0.28%via NVD
CVE-2026-86767Medium· 5.0
1w ago

Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to read pending asset re…

Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to read pending asset re…

Sunlitsnipeitapp · snipe-itEPSS 0.19%via NVD
CVE-2026-86771High· 7.6PoC
1w ago

Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() function

Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() function. Attackers can craft a maliciou…

Midnightsnipeitapp · snipe-itEPSS 0.19%via NVD
CVE-2026-86756Medium· 6.1
1w ago

Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs)

Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs). The endpoint wrote the RelayState POST parameter directly into Laravel's url.intended ses…

Sunlitsnipeitapp · snipe-itEPSS 0.20%via NVD
CVE-2026-86769Medium· 4.3
1w ago

Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id

Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. …

Sunlitsnipeitapp · snipe-itEPSS 0.16%via NVD
CVE-2026-86761Medium· 4.3PoC
1w ago

snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks

snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned…

Twilightsnipeitapp · snipe-itEPSS 0.24%via NVD
CVE-2026-86751High· 8.5PoC
1w ago

Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests

Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests. Attackers can submit markdown image syntax in checkou…

Midnightsnipeitapp · snipe-itEPSS 0.26%via NVD
CVE-2026-86746Medium· 6.4PoC
1w ago

Snipe-IT before 8.7.0 contains an authorization bypass vulnerability in Livewire components that enforce authorization only at the route level, not within component lifecycle methods

Snipe-IT before 8.7.0 contains an authorization bypass vulnerability in Livewire components that enforce authorization only at the route level, not within component lifecycle methods. Attackers with a valid authenticated session can repl…

Twilightsnipeitapp · snipe-itEPSS 0.26%via NVD
CVE-2026-86772Medium· 5.4
1w ago

Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for users without departments.view permis…

Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for users without departments.view permis…

Sunlitsnipeitapp · snipe-itEPSS 0.15%via NVD
CVE-2026-86741High· 8.5PoC
1w ago

Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field before rendering it in checkout confirmation emails

Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field before rendering it in checkout confirmation emails. Attackers with low-privilege permissions can inject markdown image syntax or raw HTML img tags pointing to …

Midnightsnipeitapp · snipe-itEPSS 0.24%via NVD
CVE-2026-86766Medium· 6.5PoC
1w ago

Snipe-IT versions up to and including 8.6.3 contain a race condition (TOCTOU) in the consumable checkout API endpoint (POST /api/v1/consumables/{consumable_id}/checkout)

Snipe-IT versions up to and including 8.6.3 contain a race condition (TOCTOU) in the consumable checkout API endpoint (POST /api/v1/consumables/{consumable_id}/checkout). The requested quantity is validated against the number of remainin…

Twilightsnipeitapp · snipe-itEPSS 0.23%via NVD
CVE-2026-86754High· 7.3
1w ago

Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated user to register OAuth clients with attacker-controlled redirect URIs

Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated user to register OAuth clients with attacker-controlled redirect URIs. Attackers can trick administrators into app…

Twilightsnipeitapp · snipe-itEPSS 0.19%via NVD
CVE-2026-86774Medium· 6.3
1w ago

Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload and delete file attachments on Asset …

Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload and delete file attachments on Asset …

Sunlitsnipeitapp · snipe-itEPSS 0.17%via NVD
CVE-2026-86752Medium· 5.4
1w ago

snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks

snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and assets.audit permi…

Sunlitsnipeitapp · snipe-itEPSS 0.18%via NVD
snipeitapp vulnerabilities (CVEs) · VulnSea