Grokability Snipe-IT是Grokability公司开源的一套开源IT资产/许可证管理系统。 Grokability Snipe-IT 8.6.1之前版本存在资源管理错误漏洞,该漏洞源于双因素认证接口缺乏速率限制、锁定和尝试计数机制,可能导致具有有效凭据的攻击者无限次猜测TOTP,成功后可获得完全认证会话,并可能禁用双因素认证。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| grokability | snipe-it | < 8.6.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| grokability | snipe-it | < 8.6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55643 | 7.6 HIGH | Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode |
| CVE-2026-55694 | 7.1 HIGH | Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover |
| CVE-2026-49976 | 6.5 MEDIUM | Snipe-IT: User Account Escalation via CSV Import |
| CVE-2026-61807 | 6.3 MEDIUM | Snipe-IT: Stored DOM XSS via table selected-count IDs |
| CVE-2026-55482 | 6.3 MEDIUM | Snipe-IT: Multi-Tenancy Bypass via Bulk Asset Update |
| CVE-2026-50550 | 5.8 MEDIUM | Snipe-IT: 2FA reset privilege bypass |
| CVE-2026-55519 | 5.4 MEDIUM | Snipe-IT: Improper Authorization in File Deletion (IDOR) |
| CVE-2026-55483 | 4.9 MEDIUM | Snipe-IT: Privilege Escalation via Missing admin Permission Check in User Creation |
| CVE-2026-55703 | 4.3 MEDIUM | Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET |
No comments yet