Snipe-IT 8.7.0 之前的版本存在一个服务器端请求伪造(SSRF)漏洞,位于 ExternalUrl 验证规则中,该规则无法检测以 IPv6 过渡地址形式编码的内网 IPv4 目标。拥有超级管理员权限的攻击者可以配置使用 NAT64、6to4 或 Teredo 等 IPv6 过渡地址的 Webhook URL,从而绕过 SSRF 防护机制,进而访问内部服务或云元数据端点。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| grokability | snipe-it | < 8.7.0 |
affected |
8.7.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| grokability | snipe-it | 0 ~ 8.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86738 | 8.7 HIGH | Snipe-IT before 8.7.0 CSS Injection via Custom CSS |
| CVE-2026-86733 | 7.2 HIGH | Snipe-IT before 8.7.0 Remote Code Execution via Backup Restore |
| CVE-2026-86734 | 6.5 MEDIUM | Snipe-IT before 8.7.1 Denial of Service via Unbounded Note Field |
| CVE-2026-86736 | 4.3 MEDIUM | snipe-it before 8.7.0 Checkout Request Counter Integrity Failure |
| CVE-2026-86737 | 4.3 MEDIUM | snipe-it before 8.7.0 Missing Authorization via barcode endpoint |
No comments yet