cbcvebase.

Grokability Snipe-It vulnerabilities

81 known vulnerabilities affecting grokability/snipe-it.

Total CVEs
81
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH22MEDIUM55LOW4

Vulnerabilities

Page 4 of 5
CVE-2026-86772P4MEDIUMCVSS 5.4≥ 8.6.3, < 8.7.02026-09-09
CVE-2026-86772 [MEDIUM] CWE-79 CVE-2026-86772: Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPres Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for users without departments.view permission. Users with departments.edit permission can inject malicious scripts into department names that execute in the
nvd
CVE-2026-88894P4MEDIUMCVSS 5.4fixed in 8.7.22026-09-10
CVE-2026-88894 [MEDIUM] CWE-863 CVE-2026-88894: Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target. Unlike the single, bulk, API, accessory, license and consumable checkout paths, App\Services\PredefinedKitCheckoutService never calls $item->canCheckoutTo($target); it only performs the actor-vs-item policy check and
nvd
CVE-2026-55515P4MEDIUMCVSS 5.0fixed in 8.6.22026-07-10
CVE-2026-55515 [MEDIUM] CWE-639 CVE-2026-55515: Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report dele Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the related checkoutable asset, allowing a reports user in one company to delete pending checkout acceptanc
nvd
CVE-2026-86753P4MEDIUMCVSS 4.3fixed in 8.7.02026-09-09
CVE-2026-86753 [MEDIUM] CWE-863 CVE-2026-86753: snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /a snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint. Authenticated users can bypass administrative restrictions and create checkout requests for non-requestable asset models by submitting requests directly to the endpoint.
nvd
CVE-2026-44831P4MEDIUMCVSS 5.4fixed in 8.4.12026-05-26
CVE-2026-44831 [MEDIUM] CWE-79 CVE-2026-44831: Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in cross-site scripting (XSS). This vulnerability is fixed in 8.4.1.
nvd
CVE-2026-86761P4MEDIUMCVSS 4.3≥ 8.6.3, < 8.7.02026-09-09
CVE-2026-86761 [MEDIUM] CWE-639 CVE-2026-86761: snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpo snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to retrieve related users, assets, accessories, consumables, and components regard
nvd
CVE-2026-55481P4MEDIUMCVSS 4.8fixed in 8.6.22026-07-10
CVE-2026-55481 [MEDIUM] CWE-79 CVE-2026-55481: Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_ Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin to inject arbitrary CSS that affects authenticated users on subsequent page loads when Content Securit
nvd
CVE-2026-55462P4MEDIUMCVSS 4.3fixed in 8.6.22026-07-10
CVE-2026-55462 [MEDIUM] CWE-863 CVE-2026-55462: Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and print Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authenticated user with only users.view to see inventory and cost/order metadata from modules that direct permi
nvd
CVE-2026-55542P4MEDIUMCVSS 4.3fixed in 8.5.12026-07-08
CVE-2026-55542 [MEDIUM] CWE-862 CVE-2026-55542: Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature ima Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the S3 branch returns before the `authorize()` call used by the local-file b
nvd
CVE-2026-84206P4MEDIUMCVSS 4.3fixed in 8.7.02026-09-01
CVE-2026-84206 [MEDIUM] CWE-863 CVE-2026-84206: Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. Attackers with edit permissions can post asset identifiers to the bulk restore endpoint to undo administrator deletions and bypass intended permission separation.
nvd
CVE-2026-86736P4MEDIUMCVSS 4.3fixed in 8.7.02026-09-08
CVE-2026-86736 [MEDIUM] CWE-682 CVE-2026-86736: snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling t snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attackers can repeatedly call cancel endpoints without active requests to drive the counter negative, or sub
nvd
CVE-2026-55472P4MEDIUMCVSS 4.3fixed in 8.6.22026-07-10
CVE-2026-55472 [MEDIUM] CWE-863 CVE-2026-55472: Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Supp Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return immediately, allowing creation of a child location under a parent location from a different company. This
nvd
CVE-2026-55703P4MEDIUMCVSS 4.3fixed in 8.6.32026-08-19
CVE-2026-55703 [MEDIUM] CWE-862 CVE-2026-55703: Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same company without asset or maintenance permission. app/Http/Controllers/MaintenancesController.php show() renders the record without authorize(), while company-scoped route-model bi
nvd
CVE-2026-55476P4MEDIUMCVSS 4.3fixed in 8.6.02026-07-10
CVE-2026-55476 [MEDIUM] CWE-862 CVE-2026-55476: Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/ Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_admin as a URL path segment without sufficient authorization, allowing an authenticated user to supply a victim user ID and silently cancel that user’s pending asset requests. This issue
nvd
CVE-2026-55479P4MEDIUMCVSS 4.3fixed in 8.6.22026-07-10
CVE-2026-55479 [MEDIUM] CWE-863 CVE-2026-55479: Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license ch Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses but not unassign them to directly access the old checkin endpoint and reclaim a license seat assigned to another u
nvd
CVE-2026-86737P4MEDIUMCVSS 4.3fixed in 8.7.02026-09-08
CVE-2026-86737 [MEDIUM] CWE-862 CVE-2026-86737: snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset} snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and enumerate asset tags across tenants, including soft-deleted and cross-company assets.
nvd
CVE-2026-86769P4MEDIUMCVSS 4.3≥ 8.6.3, < 8.7.02026-09-09
CVE-2026-86769 [MEDIUM] CWE-282 CVE-2026-86769: Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consuma Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with consumables.checkout permission can perform checkouts that result in misattributed au
nvd
CVE-2026-86740P4LOWCVSS 3.8fixed in 8.7.02026-09-09
CVE-2026-86740 [LOW] CWE-212 CVE-2026-86740: Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesControlle Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk. Administrators performing attachment deletions receive success responses and see files hidden from listings, but the physic
nvd
CVE-2026-86763P4LOWCVSS 3.5≥ 7.0.12, ≤ 8.7.22026-09-09
CVE-2026-86763 [LOW] CWE-639 CVE-2026-86763: Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer co Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewire\Importer, mounted at the imports.index route). The component only checked the broad 'import' ability at mount time, while its files() and activeFile() computed properties queried the imports table with no owner or company scope. As
nvd
CVE-2026-86739P4LOWCVSS 3.1fixed in 8.7.02026-09-09
CVE-2026-86739 [LOW] CWE-252 CVE-2026-86739: Snipe-IT 8.6.3 and earlier do not check the return value of Storage::put() when writing the signatur Snipe-IT 8.6.3 and earlier do not check the return value of Storage::put() when writing the signature PNG and the generated acceptance PDF in Account\AcceptanceController::store(). On filesystem drivers that return false instead of throwing on a write failure (for example the local disk with restrictive permissions, S3 with expired credentials, or a st
nvd
Grokability Snipe-It vulnerabilities | cvebase