Snipe-IT 在 8.7.0 之前的版本中,当向资产更新端点提交分配字段时,未能正确强制检查签出(checkout)权限。具有编辑权限但被明确拒绝签出权限的已认证用户,可以通过向 端点提交 、 或 参数,重新分配资产,从而绕过签入(check-in)流程并修改托管记录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| grokability | snipe-it | 8.6.3 ~ 8.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86741 | 8.5 HIGH | Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Category EULA |
| CVE-2026-86751 | 8.5 HIGH | Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Markdown |
| CVE-2026-86762 | 8.1 HIGH | Snipe-IT before 8.7.0 Authentication Bypass via API Middleware |
| CVE-2026-86770 | 8.1 HIGH | Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation |
| CVE-2026-86750 | 7.7 HIGH | snipe-it before 8.7.0 Authorization Bypass via API User Create/Update |
| CVE-2026-86771 | 7.6 HIGH | Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num |
| CVE-2026-86754 | 7.3 HIGH | Snipe-IT before 8.7.0 Authorization Bypass via OAuth Clients |
| CVE-2026-86759 | 7.1 HIGH | Snipe-IT before 8.7.0 Missing Authorization via asset-history CSV importer |
| CVE-2026-86766 | 6.5 MEDIUM | Snipe-IT 8.6.3 Race Condition via Consumable Checkout |
| CVE-2026-86757 | 6.5 MEDIUM | Snipe-IT before 8.7.0 Information Disclosure via Custom Fields |
| CVE-2026-86764 | 6.5 MEDIUM | Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components |
| CVE-2026-86758 | 6.5 MEDIUM | Snipe-IT before 8.7.0 License Key Exposure via CSV Export |
| CVE-2026-86742 | 6.5 MEDIUM | Snipe-IT before 8.7.0 CSV Formula Injection via Asset Acceptance Report |
| CVE-2026-86745 | 6.5 MEDIUM | Snipe-IT before 8.7.0 CSV Formula Injection via Location-Scoping Export |
| CVE-2026-86746 | 6.4 MEDIUM | Snipe-IT before 8.7.0 Authorization Bypass via Livewire Snapshot Replay |
| CVE-2026-86774 | 6.3 MEDIUM | Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy |
| CVE-2026-86749 | 6.3 MEDIUM | snipe-it before 8.7.0 Data Loss via Failed Image Write |
| CVE-2026-86756 | 6.1 MEDIUM | Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState |
| CVE-2026-86748 | 6.1 MEDIUM | Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive |
| CVE-2026-86768 | 5.4 MEDIUM | Snipe-IT before 8.7.0 Improper Input Validation via API Checkout |
Showing top 20 of 36 CVEs. View all on vendor page → →
No comments yet