These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-63498 is a high-severity vulnerability in Snipe-IT, an IT asset/license management system. An authenticated user with file-management access can upload XML and XSLT attachments and execute JavaScript in the Snipe-IT origin, allowing for same-origin data access and authenticated actions with the victim's privileges. The vulnerability is exploitable when a victim opens an attachment URL, allowing t [truncated]
CVE-2026-63493 is a high-severity vulnerability in Snipe-IT, an IT asset/license management system. An attacker can exploit this vulnerability to gain unauthorized access to sensitive resources. The vulnerability is fixed in version 8.7.0. A password-authenticated session for an account with self.api permission can reach the personal-access-token API flow before completing the account's second-factor chal [truncated]
CVE-2026-62368 is a high-severity vulnerability in Snipe-IT, an IT asset/license management system. A user with customfields.create permission can store markup in CustomField.name, which is then unescaped and executed as a bootstrap-table header title when another user views an asset-list page associated with the fieldset. This can lead to same-origin data exposure and authenticated actions with the victi [truncated]
A vulnerability in Snipe-IT's predefined kit checkout path allows for a potential authorization bypass when Full Multiple Company Support (FMCS) is enabled. This issue may permit a non-superuser with assets.checkout permission and membership in at least two companies to assign assets from one company to a user in another company, bypassing company-mismatch checks present in other checkout paths. The vulne [truncated]
CVE-2026-86774 is a broken access control vulnerability in Snipe-IT versions before 8.7.0. The vulnerability exists in the AssetModelPolicy where the files() method allows authenticated users to upload and delete file attachments on Asset Model records without the required models.files permission. This issue allows attackers with only assets.files permission to mutate shared model file attachments across [truncated]
CVE-2026-86773 is a vulnerability in Snipe-IT versions prior to 8.7.0, where an authenticated user with kits.edit permission can attach unauthorized License, Consumable, Accessory, or Asset Model to a Predefined Kit, disclosing the attached object's name. The issue arises from a lack of object-level authorization in certain endpoints, allowing low-privilege users to bypass intended access controls. This v [truncated]
CVE-2026-86772 is a stored cross-site scripting vulnerability in Snipe-IT versions before 8.7.0. The vulnerability exists in the DepartmentPresenter::formattedNameLink() method where department names are rendered unescaped in the fallback branch for users without departments.view permission. Users with departments.edit permission can inject malicious scripts into department names that execute in the brows [truncated]
CVE-2026-86771 is a high-severity vulnerability in Snipe-It versions before 8.7.0, allowing attackers with users.edit permission to inject img tags into the acceptance PDF generator. This could potentially trigger server-side requests to internal services or external targets. Defenders should assess exposure and prioritize upgrading to version 8.7.0 or later. The vulnerability exists due to a lack of HTML [truncated]
CVE-2026-86770 is a high-severity vulnerability in Snipe-IT versions before 8.7.0, allowing attackers to bypass SAML authentication and potentially takeover accounts through federated login paths, including SAML, LDAP, and OAuth. This vulnerability is caused by the default utf8mb4_unicode_ci database collation, which allows attackers to register IdP accounts with accent or case variants of victim username [truncated]
CVE-2026-86769 is an improper ownership management vulnerability in Snipe-IT versions before 8.7.0. Authenticated attackers with consumables.checkout permission can misattribute audit trail entries, obscuring which operator performed actions. This vulnerability allows attackers to manipulate audit trails, potentially hiding malicious activities. Defenders should assess exposure and verify inventory to ens [truncated]
CVE-2026-86768 is a vulnerability in Snipe-IT versions prior to 8.7.0, where the API checkout endpoints fail to validate soft-deleted states. This allows authenticated users with checkout permissions to bind live inventory to trashed targets, potentially corrupting the asset ledger and audit trails. The vulnerability has a medium severity and affects Snipe-IT deployments. IT asset managers, security teams [truncated]
CVE-2026-86767 is a vulnerability in Snipe-IT versions before 8.7.0 that allows authenticated users with assets.view permission to read pending asset requests from all companies when Full Multiple Company Support is enabled. This vulnerability impacts Snipe-IT deployments with multiple companies and asset requests, potentially allowing unauthorized access to sensitive asset information. Defenders should a [truncated]
CVE-2026-86766 is a high-severity vulnerability in Snipe-IT versions up to and including 8.6.3, which allows an authenticated user to over-allocate stock by exploiting a race condition in the consumable checkout API endpoint. This issue is fixed in version 8.7.0. The vulnerability arises from a race condition (TOCTOU) in the consumable checkout API endpoint, allowing concurrent checkout requests to succee [truncated]
CVE-2026-86765 debrief: Snipe-IT asset update endpoint authorization bypass allows authenticated users with edit permission but denied checkout permission to reassign assets, bypass check-in procedures, and alter custody records. Snipe-IT administrators and users with edit permissions should assess exposure and verify version to prevent potential security breaches. Required defensive actions include verif [truncated]
CVE-2026-86764 is a permission bypass vulnerability in Snipe-IT versions prior to 8.7.0. An authenticated user with only the assets.view permission can enumerate component details, including IDs, names, assigned quantities, and notes, via the GET /api/v1/hardware/<asset-id>/assigned/components endpoint. The components.view permission is not enforced for the returned data, only for the available_actions.vi [truncated]
CVE-2026-86763 is an authorization bypass vulnerability in Snipe-IT versions >= 7.0.12 and <= 8.6.3, affecting the Livewire importer component. This issue allows authenticated non-superusers with the 'import' permission to view all Import records and load preview data from other users' records, potentially exposing sensitive information such as personal data, asset serial numbers, and license keys.
CVE-2026-86762 is a high-severity vulnerability in Snipe-It versions prior to 8.7.0. The issue arises from the lack of application of the CheckUserIsActivated middleware to the `api` middleware group, allowing deactivated users' existing API tokens to remain valid, granting continued access to the REST API at the user's prior permission level until the token expires. This can lead to unauthorized access a [truncated]
CVE-2026-86761 is an authorization bypass vulnerability in Snipe-It versions before 8.7.0. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to retrieve related users, assets, accessories, consumables, and components regardless of their individual model permissions. This vulnerability allows unauthorized data access, emphasizing the need for defe [truncated]
CVE-2026-86760 is an incorrect authorization vulnerability affecting Snipe-IT versions 8.2.0 through 8.6.x, which was fixed in version 8.7.0. An authenticated non-admin user with the users.edit permission can toggle the activated flag on any user, including admin and superuser accounts, via a PUT request to /users/{id}. This can lock out admin accounts until another admin or superuser re-enables them.
CVE-2026-86759 is a high-severity vulnerability in Snipe-IT versions before 8.7.0, allowing any authenticated user to reassign arbitrary assets and modify audit logs via the POST /hardware/history endpoint. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail entries, compromising inventory integrity and accountability.
CVE-2026-86758 is a vulnerability in Snipe-IT before version 8.7.0, where the viewKeys authorization gate is not properly enforced in CSV export and API index endpoints. This allows authenticated users with only licenses.view permission to access product keys. The vulnerability has a CVSS score of 7.1 and is considered HIGH severity. The CVE record was published on 2026-09-09T14:17:25.430Z and has not bee [truncated]
CVE-2026-86756 is an open redirect vulnerability in Snipe-IT versions 8.5.0 through 8.6.3. The vulnerability exists in the SAML assertion-consumer endpoint and allows an unauthenticated attacker to redirect a user's browser to an arbitrary external URL after a successful authentication. This facilitates credential-harvesting phishing. Only deployments with SAML SSO enabled are affected. The issue was fixe [truncated]
CVE-2026-86755 is a medium-severity vulnerability affecting Snipe-IT versions 4.2.0 through 8.6.3. The issue arises from the exposure of Laravel Passport's auto-registered personal-access-token routes without proper permission gates, allowing users to mint long-lived bearer tokens for their own accounts, potentially bypassing administrative controls intended to restrict API access.
CVE-2026-86754 is a high-severity vulnerability in Snipe-IT versions before 8.7.0, allowing authenticated users to register OAuth clients with attacker-controlled redirect URIs. This could lead to unauthorized access with admin API permissions lasting up to 40 years. Defenders should verify exposure, prioritize remediation, and monitor API activity. The vulnerability exists due to improper gating of Larav [truncated]
CVE-2026-86751 is a high-severity vulnerability in Snipe-IT versions before 8.7.0, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests via malicious markdown image syntax in note fields. The vulnerability exists due to improper sanitization of markdown image syntax in note fields, which can be exploited by attackers to exfiltrate sensitive files and perform serv [truncated]
CVE-2026-86750 is a high-severity vulnerability in Snipe-IT versions <= 8.6.3, where the application does not validate company assignment authorization before persisting user records via the REST API. This allows a non-superuser with users.create or users.edit permissions to create or relocate user accounts across tenant boundaries, potentially leading to unauthorized user account creation and relocation. [truncated]
A transient storage failure during image upload in Snipe-IT versions <= 8.6.3 can cause unrecoverable loss of the prior image and a durable inconsistency between the database and disk. This issue is triggered when any legitimate authenticated user submits an image upload while the storage backend transiently fails. The result requires manual reconciliation.
CVE-2026-86748 is a medium-severity vulnerability in Snipe-IT versions before 8.7.0 that can lead to permanent data loss. The vulnerability exists in the restore endpoint, which wipes the database before validating the uploaded backup archive. Superusers uploading corrupted or invalid zip files can trigger this issue with no recovery path or rollback mechanism. Snipe-It administrators and security teams s [truncated]
CVE-2026-86747 is a vulnerability in Snipe-IT, an open-source IT asset management system. In versions up to and including 8.6.3, certain report acceptance endpoints are not correctly scoped when Full Multiple Company Support (FMCS) is enabled, allowing an authenticated user with the reports.view permission to send acceptance-reminder emails for, and permanently delete, any pending acceptance record in the [truncated]
CVE-2026-86746 is an authorization bypass vulnerability in Snipe-IT before 8.7.0, existing in Livewire components. Attackers with a valid authenticated session can exploit this vulnerability to escalate privileges by replaying signed component snapshots to invoke protected methods, potentially leading to unauthorized access to sensitive admin data and creation of OAuth clients and personal access tokens. [truncated]