cbcvebase.

Snipeitapp Snipe-It vulnerabilities

74 known vulnerabilities affecting snipeitapp/snipe-it.

Total CVEs
74
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH22MEDIUM49LOW1

Vulnerabilities

Page 2 of 4
CVE-2026-55460P3HIGHCVSS 7.1fixed in 8.6.22026-07-10
CVE-2026-55460 [HIGH] CWE-863 CVE-2026-55460: Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user w Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and users.edit but without users.delete can directly POST to /users/bulksave with delete_user=1 because BulkUsersController::destroy() authorizes only update, allowing the user to soft-delete another non-admin user. This issue is fixed in
nvd
CVE-2026-48492P3MEDIUMCVSS 6.5fixed in 8.6.02026-07-08
CVE-2026-48492 [MEDIUM] CWE-862 CVE-2026-48492: Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/ Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log into Snipe-IT - regardless of permissions - can retrieve a paginated list of all user accounts using only their web session cookie. No API token or elevated permissions ar
nvd
CVE-2026-38533P3MEDIUMCVSS 6.5v8.4.02026-04-14
CVE-2026-38533 [MEDIUM] CWE-285 CVE-2026-38533: An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request.
nvd
CVE-2026-48507P3HIGHCVSS 7.1fixed in 8.6.02026-06-08
CVE-2026-48507 [HIGH] CWE-863 CVE-2026-48507: Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows a non-admin user holding only the granular `users.edit` permission to lock every admin out of the instance by editing the `activated` flag (which determines whether or not a user can login) and the `ldap_import` flag, which determines whether or not th
nvd
CVE-2026-55843P3MEDIUMCVSS 6.5fixed in 8.6.02026-07-10
CVE-2026-55843 [MEDIUM] CWE-269 CVE-2026-55843: Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through NormalizePermissionsPayloadAction and PreserveUnauthorizedPrivilegedPermissionsAction in a way that can overwrite a target user’s permissions with a sparse result, allowing an administrator updating another ad
nvd
CVE-2025-47226P4LOWCVSS 3.3PoCfixed in 8.1.02025-05-02
CVE-2025-47226 [LOW] CWE-425 CVE-2025-47226: Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information. Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
nvd
CVE-2023-5511P3HIGHCVSS 8.8fixed in 6.2.32023-10-11
CVE-2023-5511 [HIGH] CWE-352 CVE-2023-5511: Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3. Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3.
nvd
CVE-2022-1155P3HIGHCVSS 7.4fixed in 5.3.10v5.3.102022-03-30
CVE-2022-1155 [HIGH] CWE-840 CVE-2022-1155: Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.
nvd
CVE-2021-3858P4HIGHCVSS 8.8fixed in 5.3.02021-10-19
CVE-2021-3858 [HIGH] CWE-352 CVE-2021-3858: snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
nvd
CVE-2022-0579P4MEDIUMCVSS 6.5fixed in 5.3.92022-02-14
CVE-2022-0579 [MEDIUM] CWE-862 CVE-2022-0579: Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9. Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.
nvd
CVE-2022-1511P4MEDIUMCVSS 6.5fixed in 5.4.42022-04-28
CVE-2022-1511 [MEDIUM] CWE-862 CVE-2022-1511: Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4. Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.
nvd
CVE-2026-86734P4MEDIUMCVSS 6.5fixed in 8.7.12026-09-08
CVE-2026-86734 [MEDIUM] CWE-400 CVE-2026-86734: Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{ac Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{acceptance} endpoint, allowing authenticated users to submit unbounded input that reaches synchronous CommonMark rendering. Attackers can submit large note values to exhaust PHP worker CPU and cause denial of service through resource exhaustion in the m
nvd
CVE-2021-4130P4HIGHCVSS 8.8fixed in 5.3.62021-12-18
CVE-2021-4130 [HIGH] CWE-352 CVE-2021-4130: snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
nvd
CVE-2022-2997P4HIGHCVSS 8.0fixed in 6.0.102022-08-25
CVE-2022-2997 [HIGH] CWE-384 CVE-2022-2997: Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10. Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10.
nvd
CVE-2026-55475P4MEDIUMCVSS 5.7fixed in 8.6.12026-07-10
CVE-2026-55475 [MEDIUM] CWE-863 CVE-2026-55475: Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modification of import ownership metadata. This issue is fixed in version 8.6.1.
nvd
CVE-2026-48493P4MEDIUMCVSS 5.5fixed in 8.6.02026-06-23
CVE-2026-48493 [MEDIUM] CWE-863 CVE-2026-48493: Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only user Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PATCH to /api/v1/users/{their_own_id} and grant themselves any permission except admin and superuser — for example `assets.view`, `assets.create`, `reports.view`, import, etc. The issue is patched in version 8.6.0.
nvd
CVE-2026-19579P4MEDIUMCVSS 5.4fixed in 8.6.02026-08-11
CVE-2026-19579 [MEDIUM] CWE-639 CVE-2026-19579: Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the ass Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated, low-privileged user can supply a non-emp
nvd
CVE-2026-55478P4MEDIUMCVSS 5.4fixed in 8.6.22026-07-10
CVE-2026-55478 [MEDIUM] CWE-639 CVE-2026-55478: Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licens Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but does not authorize access to the referenced license object, allowing a low-privilege user with predefined-kit permissions to bind a license they should not be able to access or manage into a kit. This iss
nvd
CVE-2026-86735P4MEDIUMCVSS 5.0fixed in 8.7.02026-09-08
CVE-2026-86735 [MEDIUM] CWE-918 CVE-2026-86735: snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUr snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets. Attackers with super-admin privileges can configure webhook URLs using NAT64, 6to4, or Teredo transition addresses to bypass SSRF guards and access interna
nvd
CVE-2026-55464P4MEDIUMCVSS 5.4fixed in 8.6.22026-07-10
CVE-2026-55464 [MEDIUM] CWE-79 CVE-2026-55464: Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but d Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user with assets.edit permission to place a malicious link in a markdown-textarea custom field that executes arbitrary JavaScript when another user opens the asset detail page and cli
nvd
Snipeitapp Snipe-It vulnerabilities | cvebase