snipe/snipe-it
Packagist60 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting snipe/snipe-itpage 2 of 2
- CVE-2026-49976MEDIUMCVSS 6.5EG 6.5✓ Fixed in 8.6.02026-06-23
vulnerable: 3.2.0 ... v8.5.0 (276 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update mode to overwrite the email address of a non-admin user and then request a password reset to take over that account. ap…
- CVE-2026-50550MEDIUMCVSS 5.8EG 5.8✓ Fixed in 8.5.02026-06-23
vulnerable: 3.2.0 ... v8.4.1 (275 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmin's two-factor authentication through app/Http/Controllers/Api/UsersController.php postTwoFactorReset(). The endpoint a…
- CVE-2026-54329HIGHCVSS 7.7EG 7.7✓ Fixed in 8.6.22026-06-23
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in …
- CVE-2026-55482MEDIUMCVSS 6.3EG 6.3✓ Fixed in 8.4.22026-06-23
vulnerable: 3.2.0 ... v8.4.1 (275 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/BulkAssetsController.php update() to submit company_id directly without Company::getIdForCurrentUser(), allowing assets…
- CVE-2026-55483MEDIUMCVSS 4.9EG 4.9✓ Fixed in 8.6.02026-06-23
vulnerable: 3.2.0 ... v8.5.0 (276 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission can submit the admin permission while creating a user because store() in app/Http/Controllers/Users/UsersController.php s…
- CVE-2026-55519MEDIUMCVSS 5.4EG 5.4✓ Fixed in 8.4.12026-06-23
vulnerable: 3.2.0 ... v8.4.0 (274 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside the user's ownership or company assignment. The destroy() methods in ap…
- CVE-2026-55542MEDIUMCVSS 4.3EG 4.3✓ Fixed in 8.5.12026-06-23
vulnerable: 3.2.0 ... v8.5.0 (276 versions)
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obta…
- CVE-2026-55694HIGHCVSS 7.1EG 7.1✓ Fixed in 8.6.32026-08-19
vulnerable: 3.2.0 ... v8.6.2 (279 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /api/v1/users/{target_id}/eulas to obtain another user's randomized EULA filename and then download the signed file through /account/stored-eu…
- CVE-2026-55703MEDIUMCVSS 4.3EG 4.3✓ Fixed in 8.6.32026-08-19
vulnerable: 3.2.0 ... v8.6.2 (279 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same company without asset or maintenance permission. app/Http/Controlle…
- CVE-2026-61807MEDIUMCVSS 6.3EG 6.3✓ Fixed in 8.6.22026-08-19
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the table component $name becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-side…
Check whether snipe/snipe-it is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for snipe/snipe-it CVEs against the assets you own.
Start Free Scan →