VYPR

Vendor CVEs

Grokability

All CVEs

69 total · sorted by risk
  • CVE-2026-86735MedSep 8, 2026
    risk 0.26cvss 5.0epss 0.00

    snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets. Attackers with super-admin privileges can configure webhook URLs using NAT64, 6to4,…

  • CVE-2026-55515MedJul 10, 2026
    risk 0.26cvss 5.0epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the related checkoutable asset,…

  • CVE-2026-44831MedMay 26, 2026
    risk 0.24cvss 4.8epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in cross-site scripting (XSS). This vulnerability is fixed in 8.4.1.

  • CVE-2026-86761MedSep 9, 2026
    risk 0.21cvss 4.3epss 0.00

    snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to…

  • CVE-2026-86753MedSep 9, 2026
    risk 0.21cvss 4.3epss 0.00

    snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint. Authenticated users can bypass administrative restrictions and create checkout requests for non-requestable asset models by…

  • CVE-2026-86737MedSep 8, 2026
    risk 0.21cvss 4.3epss 0.00

    snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and enumerate asset tags across tenants, including soft-deleted and cross-company assets.

  • CVE-2026-86736MedSep 8, 2026
    risk 0.21cvss 4.3epss 0.00

    snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attackers can repeatedly call cancel…

  • CVE-2026-84206MedSep 1, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. Attackers with edit permissions can post asset identifiers to the bulk restore endpoint to…

  • CVE-2026-55703MedAug 19, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same company without asset or maintenance permission. app/Http/Controllers/MaintenancesController.php show()…

  • CVE-2026-55479MedJul 10, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses but not unassign them to directly access…

  • CVE-2026-55462MedJul 10, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an authenticated user with only users.view…

  • CVE-2026-55476MedJul 10, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_admin as a URL path segment without sufficient authorization, allowing an authenticated user to supply a victim…

  • CVE-2026-55472MedJul 10, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return immediately, allowing creation of…

  • CVE-2026-55542MedJul 8, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the…

  • CVE-2026-86740LowSep 9, 2026
    risk 0.18cvss 3.8epss 0.00

    Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk. Administrators performing attachment deletions…

  • CVE-2026-86763LowSep 9, 2026
    risk 0.16cvss 3.5epss 0.00

    Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewire\Importer, mounted at the imports.index route). The component only checked the broad 'import' ability at mount time, while its files() and activeFile()…

  • CVE-2026-86739LowSep 9, 2026
    risk 0.13cvss 3.1epss 0.00

    Snipe-IT 8.6.3 and earlier do not check the return value of Storage::put() when writing the signature PNG and the generated acceptance PDF in Account\AcceptanceController::store(). On filesystem drivers that return false instead of throwing on a write failure (for example the…

  • CVE-2026-86744LowSep 9, 2026
    risk 0.07cvss 2.2epss 0.00

    Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) contain a race condition in the asset checkout paths. Api\AssetsController::checkout() and Assets\AssetCheckoutController::store() call Asset::availableForCheckout() outside the mutation path and then…

  • CVE-2025-63601CriNov 5, 2025
    risk 0.00cvss 9.9epss 0.01

    Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and execute system commands.

Page 2 of 2