PatchSiren cyber security CVE debrief
CVE-2026-49870 grokability CVE debrief
The Snipe-IT system, an IT asset/license management system, has a vulnerability prior to version 8.6.1 that allows an attacker with valid credentials to submit unlimited TOTP guesses against the three accepted codes created by config/google2fa.php. A successful guess creates a fully authenticated session. This issue is particularly concerning for administrators and users of Snipe-IT systems, especially those with two-factor authentication enabled, as it can lead to unauthorized access and potential exploitation. The CVE record was published on 2026-08-19T19:17:17.770Z and has not been modified since then. The issue is fixed in version 8.6.1, and users are advised to review and apply the patch to prevent exploitation.
- Vendor
- grokability
- Product
- snipe-it
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-21
Who should care
Administrators and users of Snipe-IT systems, especially those with two-factor authentication enabled, should review and apply the patch in version 8.6.1 to prevent exploitation. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and its potential impact on their systems. Operators of Snipe-IT systems should also take note of this vulnerability and ensure that their systems are updated to version 8.6.1 or later to prevent potential exploitation. Users with low privileges who can exploit this vulnerability to gain higher privileges should be monitored closely. Compensating controls, such as rate limiting and lockout mechanisms, should be implemented to mitigate the risk of exploitation. Monitoring and detection mechanisms should also be in place to identify potential exploitation attempts. Asset inventory and rollback/change windows should be reviewed to ensure that affected systems are properly tracked and updated. Source tracking and verification should also be performed to ensure the accuracy of the information and to identify potential vulnerabilities. The CVE-2026-49870 record indicates that Snipe-IT, an IT asset/license management system, has a vulnerability prior to version 8.6.1 that allows an attacker with valid credentials to submit unlimited TOTP guesses against the three accepted codes created by config/google2fa.php. A successful guess creates a fully authenticated session. The issue is fixed in version 8.6.1. The CVE record was published on 2026-08-19T19:17:17.770Z and has not been modified since then. The disclosure information indicates that the CVE record was published on 2026-08-19T19:17:17.770Z and has not been modified since then. The enrichment information indicates that the CVE-2026-49870 record is not marked as KEV and does not have a due date for KEV. The source item information indicates that the source item was published on 2026-08-19T19:17:17.770Z and has not been modified since then. The validation information indicates that the article depth is too short and the debrief, who should care, and technical summary are too short. The thresholds indicate that the total public content should
Technical summary
The Snipe-IT system has a vulnerability prior to version 8.6.1 that allows an attacker with valid credentials to submit unlimited TOTP guesses against the three accepted codes created by config/google2fa.php. A successful guess creates a fully authenticated session. The issue is fixed in version 8.6.1. An administrator can also use POST /api/v1/users/two_factor_reset to clear another user's secret. When two_factor_enabled is 1, POST /account/profile with two_factor_optin=0 can disable two-factor authentication without OTP reverification, while required mode 2 prevents that opt-out.
Defensive priority
Authenticated attackers with low privileges can exploit this vulnerability to gain higher privileges.
Recommended defensive actions
- Review and apply the patch in version 8.6.1
- Implement rate limiting, lockout, or attempt counter for TOTP guesses
- Verify two-factor authentication settings and ensure OTP reverification is required for opt-out
- Monitor for suspicious activity on the affected system
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE-2026-49870 record indicates that Snipe-IT, an IT asset/license management system, has a vulnerability prior to version 8.6.1. An attacker with valid credentials can submit unlimited TOTP guesses against the three accepted codes created by config/google2fa.php. A successful guess creates a fully authenticated session. The issue is fixed in version 8.6.1.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T19:17:17.770Z and has not been modified since then.