grokability snipe-it
49 known vulnerabilities in grokability snipe-it, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-63498 CVSS 5.4 medium Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET…
- CVE-2026-63493 CVSS 8.6 high Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api…
- CVE-2026-62368 CVSS 8.4 high Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in…
- CVE-2026-88894 CVSS 5.3 medium Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target…
- CVE-2026-86774 CVSS 5.3 medium Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from…
- CVE-2026-86773 CVSS 5.3 medium Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updateAccessory, and…
- CVE-2026-86772 CVSS 5.1 medium Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where…
- CVE-2026-86771 CVSS 8.3 high Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF generator, allowing attackers with…
- CVE-2026-86770 CVSS 8.6 high Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as…
- CVE-2026-86769 CVSS 5.3 medium Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that…
- CVE-2026-86768 CVSS 5.3 medium Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout…
- CVE-2026-86767 CVSS 5.3 medium Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company…
- CVE-2026-86766 CVSS 7.1 high Snipe-IT versions up to and including 8.6.3 contain a race condition (TOCTOU) in the consumable checkout API endpoint (POST…
- CVE-2026-86765 CVSS 7.1 high Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset update endpoint…
- CVE-2026-86764 CVSS 7.1 high Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET…
- CVE-2026-86763 CVSS 5.1 medium Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewire\Importer…
- CVE-2026-86762 CVSS 8.6 high Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php, and…
- CVE-2026-86761 CVSS 5.3 medium snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model…
- CVE-2026-86760 CVSS 5.3 medium Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in…
- CVE-2026-86759 CVSS 7.1 high Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign…
- CVE-2026-86758 CVSS 7.1 high Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing…
- CVE-2026-86757 CVSS 7.1 high Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field values in asset form templates for listbox, textarea…
- CVE-2026-86756 CVSS 5.3 medium Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST…
- CVE-2026-86755 CVSS 5.3 medium Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE…
- CVE-2026-86754 CVSS 8.5 high Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated user to…
- CVE-2026-86753 CVSS 5.3 medium snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId}…
- CVE-2026-86752 CVSS 5.3 medium snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering…
- CVE-2026-86751 CVSS 8.4 high Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary…
- CVE-2026-86750 CVSS 8.3 high Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment authorization before persisting user records via the REST…
- CVE-2026-86749 CVSS 7.0 high Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of storage write operations in…