Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-63493— Snipe-IT: 2FA bypass via the API token flow

Quick assessment

Affected
grokability snipe-it
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Snipe-IT 是一款 IT 资产/许可管理系统。在版本 8.7.0 之前,具有 self.api 权限的账户在尚未完成第二因素认证挑战的情况下,其通过密码验证建立的会话仍可访问 personal-access-token API 流程。这是因为 CheckForTwoFactor 中间件仅在 Web 中间件组中生效,而在 API 中间件组中未生效。 根据安全通告,由此产生的持久性 API 令牌能够以受害者的权限读取和修改资源;对于管理员账户,该令牌还可访问 users/two_factor_reset 端点。重

CVSS 8.6 · High EPSS 0.27% · P17

Affected Version Matrix 1

VendorProduct Version RangeStatus
grokability snipe-it < 8.7.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-63493

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Snipe-IT: 2FA bypass via the API token flow
Source: CVE Program / CVE List V5
Vulnerability Description
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-token API flow before completing the account's second-factor challenge because CheckForTwoFactor is enforced in the web middleware group but not the API middleware group. The advisory states that the resulting persistent API token can read and modify resources with the victim's permissions and, for an administrator, can reach the users/two_factor_reset endpoint. Resetting the administrator's enrolled second factor allows the password-holding attacker to enroll an attacker-controlled factor, take over the administrator's web account, and lock out the legitimate user. The token does not create a web session, but it provides broad API access while the same browser session remains blocked at the two-factor page. This vulnerability is fixed in 8.7.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用候选路径或通道进行的认证绕过
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
grokability snipe-it < 8.7.0 -

II. Public POCs for CVE-2026-63493

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63493

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-63493 (3)

Vendor Advisories for CVE-2026-63493 (1)

Vendor Pages for CVE-2026-63493 (1)

Same Patch Batch · grokability · 2026-09-24 · 3 CVEs total

CVE-2026-63498 8.7 HIGH Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API
CVE-2026-62368 8.1 HIGH Snipe-IT: Stored XSS via Custom Field name in asset-list column headers

IV. Related Vulnerabilities

V. Comments for CVE-2026-63493

No comments yet


Leave a comment