在 8.7.0 版本之前的 Snipe-IT 中,GET /hardware/{asset}/barcode 端点未强制执行资产查看权限。已认证的恶意用户可通过遍历资产 ID 来获取条码,并枚举来自不同租户(包括已逻辑删除资产和跨公司资产)的资产标签。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| grokability | snipe-it | < 8.7.0 |
affected |
8.7.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| grokability | snipe-it | 0 ~ 8.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86738 | 8.7 HIGH | Snipe-IT before 8.7.0 CSS Injection via Custom CSS |
| CVE-2026-86733 | 7.2 HIGH | Snipe-IT before 8.7.0 Remote Code Execution via Backup Restore |
| CVE-2026-86734 | 6.5 MEDIUM | Snipe-IT before 8.7.1 Denial of Service via Unbounded Note Field |
| CVE-2026-86735 | 5.0 MEDIUM | snipe-it before 8.7.0 SSRF via IPv6 transition address bypass |
| CVE-2026-86736 | 4.3 MEDIUM | snipe-it before 8.7.0 Checkout Request Counter Integrity Failure |
No comments yet