PatchSiren

grokability CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM grokability CVE published 2026-09-09

CVE-2026-86745

CVE-2026-86745 is a vulnerability in Snipe-IT, an IT asset management application. The issue arises from the SettingsController::downloadLocationScopingReport function, which streams a location-scoping mismatch report as a CSV file without properly escaping formulas. This allows an authenticated user with create/edit rights to inject spreadsheet formulas into free-text fields, enabling data exfiltration o [truncated]

LOW grokability CVE published 2026-09-09

CVE-2026-86744

CVE-2026-86744 is a low-severity vulnerability in Snipe-IT versions 8.6.3 and earlier, as well as pre-release commits prior to the fix. The vulnerability is caused by a race condition in the asset checkout paths, which can lead to duplicate checkout-history rows, a doubled checkout_counter, and two CheckoutableCheckedOut events for a single-assignment asset. This can corrupt the audit trail and utilizatio [truncated]

MEDIUM grokability CVE published 2026-09-09

CVE-2026-86743

CVE-2026-86743 is a vulnerability in Snipe-IT versions before 8.7.0 that allows authenticated users to read pending asset acceptances across all companies. This issue arises from improper scoping of asset acceptance report queries by company, enabling reports.view users to access unaccepted_assets report pages or CSV exports without per-row access validation. As a result, attackers can disclose cross-comp [truncated]

MEDIUM grokability CVE published 2026-09-09

CVE-2026-86742

CVE-2026-86742 is a medium-severity vulnerability in Snipe-IT versions prior to 8.7.0, where an authenticated low-privilege user can inject malicious formulas into the 'unaccepted assets' acceptance report CSV export. This can be done by setting certain fields to values beginning with =, +, -, @, tab, or CR. When the CSV is opened in spreadsheet software, the injected content is evaluated as a formula, po [truncated]

HIGH grokability CVE published 2026-09-09

CVE-2026-86741

CVE-2026-86741 is a high-severity vulnerability in Snipe-It versions before 8.7.0, allowing attackers with low-privilege permissions to inject malicious code into category EULA text fields. This can lead to sensitive file exfiltration and SSRF attacks. Defenders should prioritize patching Snipe-It instances to version 8.7.0 or later and verify that category EULA text fields are properly sanitized to preve [truncated]

MEDIUM grokability CVE published 2026-09-09

CVE-2026-86740

CVE-2026-86740 is a medium-severity vulnerability in Snipe-IT versions before 8.7.0. An attacker can delete attachments and receive success responses, but the files remain on disk, accessible to those with filesystem or backup access. This issue arises from Snipe-IT's failure to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api/UploadedFilesController::destroy(). Ad [truncated]

LOW grokability CVE published 2026-09-09

CVE-2026-86739

CVE-2026-86739 is a vulnerability in Snipe-IT versions 8.6.3 and earlier. An authenticated user can trigger the condition by completing an acceptance while the storage backend is silently failing writes, resulting in an acceptance record marked complete without supporting evidence files. This yields a materially incomplete compliance artifact for EULA acknowledgement or equipment-receipt workflows. The vu [truncated]

MEDIUM grokability CVE published 2026-09-01

CVE-2026-84206

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-01T16:17:35.607Z and has not been modified since then. CVE-2026-84206 is an authorization bypass vulnerability in Snipe-IT before version 8.7.0. The bulk asset restore endpoint is gated on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-delet [truncated]

MEDIUM grokability CVE published 2026-08-19

CVE-2026-61807

A stored cross-site scripting (XSS) vulnerability exists in Snipe-IT, an IT asset/license management system, prior to version 8.6.2. The vulnerability is triggered when a crafted manufacturer or supplier name is passed as the table component $name and becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-side code reads the browser-decoded countId, uses it as a selec [truncated]

HIGH grokability CVE published 2026-08-19

CVE-2026-55694

CVE-2026-55694 is a vulnerability in Snipe-IT, an IT asset/license management system, that allows a restricted user to obtain another user's randomized EULA filename and download the signed file. The issue is fixed in version 8.6.3. This vulnerability impacts Snipe-IT deployments, requiring defenders to assess exposure and apply the patch to prevent unauthorized access to EULA files. The vulnerability ari [truncated]

HIGH grokability CVE published 2026-08-19

CVE-2026-55643

A vulnerability in Snipe-IT, an IT asset/license management system, allows company-scoped users in FMCS floater mode to access users with null company_id due to inconsistent application of isCurrentUserHasAccess in API queries and bulk web actions. This issue, fixed in version 8.6.3, can expose personal data and assigned licenses, allow modification of out-of-scope profiles, and enable soft-deletion of us [truncated]

MEDIUM grokability CVE published 2026-08-19

CVE-2026-55482

CVE-2026-55482 is a vulnerability in Snipe-IT, an IT asset/license management system, that allows a non-superadmin to move assets across company boundaries, breaking multi-tenant isolation. The issue is fixed in version 8.4.1. This vulnerability exists due to improper authorization in the BulkAssetsController.php update() method, allowing unauthorized asset movement. Defenders should assess exposure and a [truncated]

MEDIUM grokability CVE published 2026-08-19

CVE-2026-50550

CVE-2026-50550 is a vulnerability in Snipe-IT, an IT asset/license management system, that allows a user who can edit other users to reset a superadmin's two-factor authentication. This issue is fixed in version 8.5.0. The vulnerability exists due to insufficient authorization checks in the postTwoFactorReset() function of the UsersController.php file, which allows for potential privilege escalation. Defe [truncated]

MEDIUM grokability CVE published 2026-08-19

CVE-2026-49976

CVE-2026-49976 is a medium-severity vulnerability in Snipe-IT, an IT asset/license management system. A user with import permission can use CSV update mode to overwrite the email address of a non-admin user and then request a password reset to take over that account. The issue is caused by the sanitizeItemForUpdating() function in app/Importer/ItemImporter.php, which rebuilds the update array from the raw [truncated]

MEDIUM grokability CVE published 2026-08-19

CVE-2026-49870

CVE-2026-49870 is a medium-severity vulnerability in Snipe-IT, an IT asset/license management system. The issue allows an attacker with valid credentials to submit unlimited TOTP guesses against the three accepted codes, potentially creating a fully authenticated session. This vulnerability is fixed in version 8.6.1. Defenders should assess exposure and apply the patch, particularly those using two-factor [truncated]

MEDIUM Grokability CVE published 2026-08-11

CVE-2026-19579

PatchSiren debrief for CVE-2026-19579 based on the supplied source corpus. The CVE record was published on 2026-08-11T21:17:35.240Z and has not been modified since then. This vulnerability affects Snipe-IT installations prior to version 8.6.0, allowing an authenticated, low-privileged user to bypass authorization checks in the asset checkout-request cancellation endpoint. The vulnerability has a CVSS scor [truncated]

MEDIUM grokability CVE published 2026-07-10

CVE-2026-55515

CVE-2026-55515 is a vulnerability in Snipe-IT, an IT asset/license management system. The unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking access to the related checkoutable asset. This allows a reports user in one company to delete pending checkout acceptance records for another company. The [truncated]

MEDIUM grokability CVE published 2026-07-10

CVE-2026-55481

CVE-2026-55481 is an issue in Snipe-IT, an IT asset/license management system, where the default.blade.php file does not properly escape HTML in header_color and related branding color settings within a CSS style block. This insufficient escaping allows a superadmin to inject arbitrary CSS, which affects authenticated users on subsequent page loads when Content Security Policy (CSP) is disabled. The issue [truncated]

MEDIUM grokability CVE published 2026-07-10

CVE-2026-55479

CVE-2026-55479 is a MEDIUM severity vulnerability in Snipe-IT prior to 8.6.2. The legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission. This allows a user who can assign licenses but not unassign them to directly access the old checkin endpoint and reclaim a license seat assigned to another user or asset. The issue is fixed in version [truncated]

MEDIUM grokability CVE published 2026-07-10

CVE-2026-55475

CVE-2026-55475 is a MEDIUM severity vulnerability in Snipe-IT's Importer API endpoint. Prior to version 8.6.1, a user with CSV import capabilities and a valid API key could overwrite the created_by value of an import file. This allowed unauthorized modification of import ownership metadata. The issue is fixed in version 8.6.1. Users of Snipe-IT asset/license management system should be aware of this vulne [truncated]

MEDIUM grokability CVE published 2026-07-10

CVE-2026-55469

CVE-2026-55469 is a path traversal vulnerability in the Snipe-IT asset/license management system. An authenticated user with import and assets.update permissions can exploit this vulnerability by placing a path traversal string in an asset image field through CSV import and then triggering image deletion. This allows for the deletion of arbitrary files accessible to the server process. The issue was fixed [truncated]

MEDIUM grokability CVE published 2026-07-10

CVE-2026-55466

CVE-2026-55466 is a vulnerability in Snipe-IT, an IT asset/license management system. Prior to version 8.6.2, the UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml. The UploadedFilesController serves attachments inline without using StorageHelper::allowSafeInline(), allowing a low-privilege user to upload active XHTML or XML content that is later served same-origin and exec [truncated]

MEDIUM grokability CVE published 2026-07-10

CVE-2026-55462

CVE-2026-55462 is a medium-severity vulnerability in Snipe-IT, an IT asset/license management system. Prior to version 8.6.2, an authenticated user with only 'users.view' permission can access inventory and cost/order metadata from modules that would otherwise be restricted. This issue is fixed in version 8.6.2. Affected product deployments should be identified and owners assigned for follow-up. Compensat [truncated]

MEDIUM grokability CVE published 2026-07-10

CVE-2026-55461

CVE-2026-55461 is an open redirect vulnerability in Snipe-IT, a popular IT asset/license management system. The vulnerability allows an attacker to redirect a Snipe-IT user to a malicious website after a legitimate user edit action. This is possible because the user edit flow stores the URL from the attacker-controlled Referer header into Laravel's intended URL session value and later uses redirect()->int [truncated]

MEDIUM grokability CVE published 2026-07-10

CVE-2026-55452

CVE-2026-55452 is a medium-severity vulnerability in Snipe-IT, an IT asset/license management system. Prior to version 8.5.0, a low-privileged authenticated user could store a formula-like User-Agent that may execute when a report viewer opens the exported CSV in spreadsheet software. The vulnerability arises from the Actionlog::logaction() function storing the request User-Agent header and ReportsControl [truncated]

HIGH grokability CVE published 2026-07-10

CVE-2026-55843

CVE-2026-55843 is a high-severity vulnerability in Snipe-IT, an IT asset/license management system. The vulnerability allows an administrator to remove a target user's administrative or granular permissions. This issue is fixed in version 8.6.0. The vulnerability is caused by the UsersController::update() method passing a missing permission request field through NormalizePermissionsPayloadAction and Prese [truncated]

MEDIUM grokability CVE published 2026-07-10

CVE-2026-55478

CVE-2026-55478 is a vulnerability in Snipe-IT, an IT asset/license management system. Prior to version 8.6.2, the system did not properly authorize access to a referenced license object when a low-privilege user with predefined-kit permissions attempted to bind a license they should not be able to access or manage into a kit. This issue has been fixed in version 8.6.2. The vulnerability allows low-privile [truncated]

MEDIUM grokability CVE published 2026-07-10

CVE-2026-55476

CVE-2026-55476 is a medium-severity vulnerability in Snipe-IT versions prior to 8.6.0. An authenticated user can exploit this issue to silently cancel pending asset requests of other users by supplying a victim user ID in the POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} endpoint. The vulnerability is addressed in Snipe-IT version 8.6.0. This issue highlights the importanc [truncated]

HIGH grokability CVE published 2026-07-10

CVE-2026-55474

CVE-2026-55474 is a high-severity vulnerability in Snipe-IT, a popular IT asset/license management system. The vulnerability, patched in version 8.5.0, allows an authenticated attacker to read arbitrary files accessible to the web server process through directory traversal in the ActionlogController::displaySig method. This issue arises from the method's failure to properly sanitize the route filename par [truncated]

MEDIUM grokability CVE published 2026-07-10

CVE-2026-55464

CVE-2026-55464 is a medium-severity vulnerability in Snipe-IT, an IT asset/license management system. An authenticated user with assets.edit permission can inject malicious JavaScript via a Markdown hyperlink in a custom field, which executes when another user views the asset details and clicks the link. The issue is fixed in version 8.6.2. This vulnerability allows for cross-site scripting (XSS) attacks, [truncated]