Snipeitapp
Snipeitapp Snipe-it: vulnerabilidades y CVE
Snipeitapp Snipe-it tiene 133 vulnerabilidades publicadas, 94 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE133
Últimos 12 meses94
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-63498 | Media (5.4) | 0.21% | — | 24 sept 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML… |
| CVE-2026-63493 | Alta (8.6) | 0.27% | — | 24 sept 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-token API flow before completing the account's… |
| CVE-2026-62368 | Alta (8.4) | 0.35% | — | 24 sept 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an… |
| CVE-2026-88894 | Media (5.3) | 0.26% | — | 10 sept 2026 | Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target. Unlike the single, bulk, API, accessory, license and consumable checkout paths,… |
| CVE-2026-86773 | Media (5.3) | 0.25% | — | 9 sept 2026 | Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updateAccessory, and updateModel endpoints and in the storeModel endpoint for Predefined Kits. The… |
| CVE-2026-86772 | Media (5.1) | 0.25% | — | 9 sept 2026 | Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for users without… |
| CVE-2026-86771 | Alta (8.3) | 0.32% | — | 9 sept 2026 | Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() function. Attackers… |
| CVE-2026-86770 | Alta (8.6) | 0.57% | — | 9 sept 2026 | Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case variants of victim… |
| CVE-2026-86768 | Media (5.3) | 0.35% | — | 9 sept 2026 | Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets. Attackers can submit POST requests… |
| CVE-2026-86767 | Media (5.3) | 0.33% | — | 9 sept 2026 | Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to… |
| CVE-2026-86766 | Alta (7.1) | 0.35% | — | 9 sept 2026 | Snipe-IT versions up to and including 8.6.3 contain a race condition (TOCTOU) in the consumable checkout API endpoint (POST /api/v1/consumables/{consumable_id}/checkout). The requested quantity is validated against the… |
| CVE-2026-86765 | Alta (7.1) | 0.40% | — | 9 sept 2026 | Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset update endpoint. Authenticated users with edit permission but explicitly denied checkout permission… |
| CVE-2026-86763 | Media (5.1) | 0.27% | — | 9 sept 2026 | Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewire\Importer, mounted at the imports.index route). The component only checked the broad 'import'… |
| CVE-2026-86762 | Alta (8.6) | 0.47% | — | 9 sept 2026 | Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php, and deactivating a user does not revoke that user's Passport personal access tokens. As a… |
| CVE-2026-86761 | Media (5.3) | 0.36% | — | 9 sept 2026 | snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can… |
| CVE-2026-86760 | Media (5.3) | 0.38% | — | 9 sept 2026 | Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/Users/UsersController::update(). The single-user edit route assigned the activated field from the… |
| CVE-2026-86758 | Alta (7.1) | 0.41% | — | 9 sept 2026 | Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys. Attackers… |
| CVE-2026-86757 | Alta (7.1) | 0.37% | — | 9 sept 2026 | Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field values in asset form templates for listbox, textarea, markdown-textarea, and date/datetime picker elements. Authenticated users with… |
| CVE-2026-86756 | Media (5.3) | 0.33% | — | 9 sept 2026 | Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs). The endpoint wrote the RelayState POST parameter directly into… |
| CVE-2026-86755 | Media (5.3) | 0.27% | — | 9 sept 2026 | Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middleware, without the… |
| CVE-2026-86753 | Media (5.3) | 0.28% | — | 9 sept 2026 | snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint. Authenticated users can bypass administrative restrictions and create… |
| CVE-2026-86752 | Media (5.3) | 0.25% | — | 9 sept 2026 | snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and… |
| CVE-2026-86751 | Alta (8.4) | 0.37% | — | 9 sept 2026 | Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests. Attackers can submit markdown image… |
| CVE-2026-86750 | Alta (8.3) | 0.33% | — | 9 sept 2026 | Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment authorization before persisting user records via the REST API. In Api\UsersController::store() and ::update(), the user record is filled… |
| CVE-2026-86748 | Media (6.9) | 0.40% | — | 9 sept 2026 | Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. Superusers uploading corrupted or invalid zip files trigger permanent data loss with no recovery… |
| CVE-2026-86747 | Media (5.3) | 0.25% | — | 9 sept 2026 | Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endpoints POST /reports/unaccepted_assets/sent_reminder… |
| CVE-2026-86746 | Alta (7.4) | 0.29% | — | 9 sept 2026 | Snipe-IT before 8.7.0 contains an authorization bypass vulnerability in Livewire components that enforce authorization only at the route level, not within component lifecycle methods. Attackers with a valid… |
| CVE-2026-86745 | Media (5.1) | 0.36% | — | 9 sept 2026 | Snipe-IT is an IT asset management application. In Snipe-IT master-branch builds after 8.6.3 (the code was never included in a tagged release), SettingsController::downloadLocationScopingReport streams the FMCS… |
| CVE-2026-86743 | Media (5.3) | 0.29% | — | 9 sept 2026 | Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the… |
| CVE-2026-86742 | Media (5.1) | 0.41% | — | 9 sept 2026 | Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export. ReportsController::postAssetAcceptanceReport builds the CSV by hand (stripping commas and joining rows… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.