« Volver al listado

Snipeitapp

Snipeitapp Snipe-it: vulnerabilidades y CVE

Snipeitapp Snipe-it tiene 133 vulnerabilidades publicadas, 94 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE133
Últimos 12 meses94
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-63498Media (5.4)0.21%—24 sept 2026
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML…
CVE-2026-63493Alta (8.6)0.27%—24 sept 2026
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-token API flow before completing the account's…
CVE-2026-62368Alta (8.4)0.35%—24 sept 2026
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an…
CVE-2026-88894Media (5.3)0.26%—10 sept 2026
Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target. Unlike the single, bulk, API, accessory, license and consumable checkout paths,…
CVE-2026-86773Media (5.3)0.25%—9 sept 2026
Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updateAccessory, and updateModel endpoints and in the storeModel endpoint for Predefined Kits. The…
CVE-2026-86772Media (5.1)0.25%—9 sept 2026
Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for users without…
CVE-2026-86771Alta (8.3)0.32%—9 sept 2026
Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() function. Attackers…
CVE-2026-86770Alta (8.6)0.57%—9 sept 2026
Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case variants of victim…
CVE-2026-86768Media (5.3)0.35%—9 sept 2026
Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets. Attackers can submit POST requests…
CVE-2026-86767Media (5.3)0.33%—9 sept 2026
Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to…
CVE-2026-86766Alta (7.1)0.35%—9 sept 2026
Snipe-IT versions up to and including 8.6.3 contain a race condition (TOCTOU) in the consumable checkout API endpoint (POST /api/v1/consumables/{consumable_id}/checkout). The requested quantity is validated against the…
CVE-2026-86765Alta (7.1)0.40%—9 sept 2026
Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset update endpoint. Authenticated users with edit permission but explicitly denied checkout permission…
CVE-2026-86763Media (5.1)0.27%—9 sept 2026
Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewire\Importer, mounted at the imports.index route). The component only checked the broad 'import'…
CVE-2026-86762Alta (8.6)0.47%—9 sept 2026
Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php, and deactivating a user does not revoke that user's Passport personal access tokens. As a…
CVE-2026-86761Media (5.3)0.36%—9 sept 2026
snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can…
CVE-2026-86760Media (5.3)0.38%—9 sept 2026
Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/Users/UsersController::update(). The single-user edit route assigned the activated field from the…
CVE-2026-86758Alta (7.1)0.41%—9 sept 2026
Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys. Attackers…
CVE-2026-86757Alta (7.1)0.37%—9 sept 2026
Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field values in asset form templates for listbox, textarea, markdown-textarea, and date/datetime picker elements. Authenticated users with…
CVE-2026-86756Media (5.3)0.33%—9 sept 2026
Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs). The endpoint wrote the RelayState POST parameter directly into…
CVE-2026-86755Media (5.3)0.27%—9 sept 2026
Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middleware, without the…
CVE-2026-86753Media (5.3)0.28%—9 sept 2026
snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint. Authenticated users can bypass administrative restrictions and create…
CVE-2026-86752Media (5.3)0.25%—9 sept 2026
snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and…
CVE-2026-86751Alta (8.4)0.37%—9 sept 2026
Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests. Attackers can submit markdown image…
CVE-2026-86750Alta (8.3)0.33%—9 sept 2026
Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment authorization before persisting user records via the REST API. In Api\UsersController::store() and ::update(), the user record is filled…
CVE-2026-86748Media (6.9)0.40%—9 sept 2026
Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery…
CVE-2026-86747Media (5.3)0.25%—9 sept 2026
Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endpoints POST /reports/unaccepted_assets/sent_reminder…
CVE-2026-86746Alta (7.4)0.29%—9 sept 2026
Snipe-IT before 8.7.0 contains an authorization bypass vulnerability in Livewire components that enforce authorization only at the route level, not within component lifecycle methods. Attackers with a valid…
CVE-2026-86745Media (5.1)0.36%—9 sept 2026
Snipe-IT is an IT asset management application. In Snipe-IT master-branch builds after 8.6.3 (the code was never included in a tagged release), SettingsController::downloadLocationScopingReport streams the FMCS…
CVE-2026-86743Media (5.3)0.29%—9 sept 2026
Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the…
CVE-2026-86742Media (5.1)0.41%—9 sept 2026
Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export. ReportsController::postAssetAcceptanceReport builds the CSV by hand (stripping commas and joining rows…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services28
  2. T1078 Valid Accounts8
  3. T1005 Data from Local System6
  4. T1059 Command and Scripting Interpreter4
  5. T1203 Exploitation for Client Execution4
  6. T1068 Exploitation for Privilege Escalation3

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.