PatchSiren

grokability CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM grokability CVE published 2026-05-26

CVE-2026-44833

An open redirect vulnerability in Snipe-IT IT asset/license management system allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. The vulnerability exists in versions prior to 8.4.1 and was fixed in version 8.4.1. The CVSS 3.1 vector indicates attack vector is adjacent network, low attack complexity, low privileges required, user interactio [truncated]

HIGH grokability CVE published 2026-05-26

CVE-2026-44832

An authenticated privilege escalation vulnerability in Snipe-IT allows users with only users.edit permission to grant themselves full administrative access. The API endpoint /api/v1/users/{id} fails to properly validate permission modifications, stripping only the superuser key while permitting admin and other elevated permissions to be set. This represents an authorization bypass where insufficient serve [truncated]

MEDIUM grokability CVE published 2026-05-26

CVE-2026-44831

A stored cross-site scripting (XSS) vulnerability exists in Snipe-IT, an open-source IT asset and license management platform. The flaw affects versions prior to 8.4.1 and resides in the unescaped rendering of the notes column within the components module. Users with component view access can trigger or be affected by this vulnerability when malicious scripts are embedded in notes fields and subsequently [truncated]