Snipe-IT 8.6.3 及更早版本在 中写入签名 PNG 和生成的验收 PDF 时,未检查 的返回值。对于某些在写入失败时返回 而不是抛出异常的存储驱动(例如:权限受限的本地磁盘、凭据过期的 S3、或配额已满的存储后端),程序会继续执行到 ,从而设置 时间戳以及 / 字段,创建“accepted”操作日志条目,并触发完成通知——尽管这些证据文件实际上从未被成功存储。其结果是:验收记录被标记为已完成,但其所依赖的证据文件并不存在,导致 EULA 确认或设备接收等工作流中的合规性交付物在实质上是不完整的。该问题在
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| grokability | snipe-it | 0 ~ 8.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86751 | 8.5 HIGH | Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Markdown |
| CVE-2026-86741 | 8.5 HIGH | Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Category EULA |
| CVE-2026-86770 | 8.1 HIGH | Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation |
| CVE-2026-86762 | 8.1 HIGH | Snipe-IT before 8.7.0 Authentication Bypass via API Middleware |
| CVE-2026-86750 | 7.7 HIGH | snipe-it before 8.7.0 Authorization Bypass via API User Create/Update |
| CVE-2026-86771 | 7.6 HIGH | Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num |
| CVE-2026-86754 | 7.3 HIGH | Snipe-IT before 8.7.0 Authorization Bypass via OAuth Clients |
| CVE-2026-86759 | 7.1 HIGH | Snipe-IT before 8.7.0 Missing Authorization via asset-history CSV importer |
| CVE-2026-86758 | 6.5 MEDIUM | Snipe-IT before 8.7.0 License Key Exposure via CSV Export |
| CVE-2026-86765 | 6.5 MEDIUM | Snipe-IT 8.6.3 Authorization Bypass via Asset Update Endpoint |
| CVE-2026-86742 | 6.5 MEDIUM | Snipe-IT before 8.7.0 CSV Formula Injection via Asset Acceptance Report |
| CVE-2026-86757 | 6.5 MEDIUM | Snipe-IT before 8.7.0 Information Disclosure via Custom Fields |
| CVE-2026-86745 | 6.5 MEDIUM | Snipe-IT before 8.7.0 CSV Formula Injection via Location-Scoping Export |
| CVE-2026-86766 | 6.5 MEDIUM | Snipe-IT 8.6.3 Race Condition via Consumable Checkout |
| CVE-2026-86764 | 6.5 MEDIUM | Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components |
| CVE-2026-86746 | 6.4 MEDIUM | Snipe-IT before 8.7.0 Authorization Bypass via Livewire Snapshot Replay |
| CVE-2026-86774 | 6.3 MEDIUM | Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy |
| CVE-2026-86749 | 6.3 MEDIUM | snipe-it before 8.7.0 Data Loss via Failed Image Write |
| CVE-2026-86756 | 6.1 MEDIUM | Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState |
| CVE-2026-86748 | 6.1 MEDIUM | Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive |
Showing top 20 of 36 CVEs. View all on vendor page → →
No comments yet