VYPR

Snipe It

by Grokability

Source repositories

CVEs (72)

  • CVE-2026-55475MedJul 10, 2026
    risk 0.30cvss 5.7epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modification of import ownership metadata. This…

  • CVE-2026-86773MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updateAccessory, and updateModel endpoints and in the storeModel endpoint for Predefined Kits. The existing check authorizes only the parent Predefined Kit (update…

  • CVE-2026-86772MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for users without departments.view permission. Users with departments.edit…

  • CVE-2026-86768MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets. Attackers can submit POST requests to hardware, component, or consumable checkout endpoints…

  • CVE-2026-86760MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/Users/UsersController::update(). The single-user edit route assigned the activated field from the request payload before evaluating the canEditAuthFields…

  • CVE-2026-86755MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middleware, without the self.api permission gate that Snipe-IT enforces on its own token…

  • CVE-2026-86752MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and assets.audit permissions could write audit log entries…

  • CVE-2026-86747MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endpoints POST /reports/unaccepted_assets/sent_reminder (ReportsController::sentAssetAcceptanceReminder) and DELETE /reports/unaccepted_assets/{acceptanceId}/delete…

  • CVE-2026-55519MedAug 19, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside the user's ownership or company assignment. The destroy() methods in app/Http/Controllers/Api/UploadedFilesContr…

  • CVE-2026-55464MedJul 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user with assets.edit permission to place a malicious link in a markdown-textarea custom field that executes…

  • CVE-2025-63743MedApr 13, 2026
    risk 0.28cvss 5.4epss 0.00

    Cross-Site Scripting vulnerability in the Snipe-IT web-based asset management system v8.3.0 to up and including v8.3.1 allows authenticated attacker with lowest privileges sufficient only to log in, to inject arbitrary JavaScript code via "Name" and "Surname" fields. The…

  • CVE-2026-86767MedSep 9, 2026
    risk 0.26cvss 5.0epss 0.00

    Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to read pending asset requests from all companies. Attackers can…

  • CVE-2026-86743MedSep 9, 2026
    risk 0.26cvss 5.0epss 0.00

    Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the unaccepted_assets report page or CSV export to disclose…

  • CVE-2026-86735MedSep 8, 2026
    risk 0.26cvss 5.0epss 0.00

    snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets. Attackers with super-admin privileges can configure webhook URLs using NAT64, 6to4,…

  • CVE-2026-55515MedJul 10, 2026
    risk 0.26cvss 5.0epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the related checkoutable asset,…

  • CVE-2026-44831MedMay 26, 2026
    risk 0.24cvss 4.8epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in cross-site scripting (XSS). This vulnerability is fixed in 8.4.1.

  • CVE-2026-86761MedSep 9, 2026
    risk 0.21cvss 4.3epss 0.00

    snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to…

  • CVE-2026-86753MedSep 9, 2026
    risk 0.21cvss 4.3epss 0.00

    snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint. Authenticated users can bypass administrative restrictions and create checkout requests for non-requestable asset models by…

  • CVE-2026-86737MedSep 8, 2026
    risk 0.21cvss 4.3epss 0.00

    snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and enumerate asset tags across tenants, including soft-deleted and cross-company assets.

  • CVE-2026-86736MedSep 8, 2026
    risk 0.21cvss 4.3epss 0.00

    snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attackers can repeatedly call cancel…