Medium severity5.4NVD Advisory· Published Sep 9, 2026
CVE-2026-86772
CVE-2026-86772
Description
Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for users without departments.view permission. Users with departments.edit permission can inject malicious scripts into department names that execute in the browsers of all department members when they load their My Assets page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <8.7.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.