snipe/snipe-it
Packagist81 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting snipe/snipe-itpage 2 of 2
- CVE-2026-49976MEDIUMCVSS 6.5EG 6.5fixed in 8.6.02026-06-23
vulnerable: 3.2.0 ... v8.5.0 (276 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update mode to overwrite the email address of a non-admin user and then request a password reset to take over that account. ap…
- CVE-2026-50550MEDIUMCVSS 6.3EG 6.3fixed in 8.5.02026-06-23
vulnerable: 3.2.0 ... v8.4.1 (275 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmin's two-factor authentication through app/Http/Controllers/Api/UsersController.php postTwoFactorReset(). The endpoint a…
- CVE-2026-54329HIGHCVSS 7.7EG 7.7fixed in 8.6.22026-06-23
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in …
- CVE-2026-55452HIGHCVSS 7.3EG 7.3fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes that value to the Activity Report CSV without formula escapin…
- CVE-2026-55460HIGHCVSS 7.1EG 7.1fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and users.edit but without users.delete can directly POST to /users/bulksave with delete_user=1 because BulkUsersController:…
- CVE-2026-55461MEDIUMCVSS 6.1EG 6.1fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the attacker-controlled Referer header into Laravel’s intended URL session value and later uses redirect()->intended(...)…
- CVE-2026-55462MEDIUMCVSS 4.3EG 4.3fixed in 8.6.12026-07-10
vulnerable: 3.2.0 ... v8.6.0 (277 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an…
- CVE-2026-55464MEDIUMCVSS 5.4EG 5.4fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user with assets.edit permission to place a malicious link in a markdo…
- CVE-2026-55466HIGHCVSS 8.7EG 8.7fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml and UploadedFilesController serves attachments inline without using StorageHelper::allowSa…
- CVE-2026-55469MEDIUMCVSS 6.5EG 6.5fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path traversal string in an asset image field through CSV import and then trigger image deletion…
- CVE-2026-55472MEDIUMCVSS 4.3EG 4.3fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not …
- CVE-2026-55474MEDIUMCVSS 6.5EG 6.5fixed in 8.5.02026-07-10
vulnerable: 3.2.0 ... v8.4.1 (275 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to t…
- CVE-2026-55475MEDIUMCVSS 5.7EG 5.7fixed in 8.6.12026-07-10
vulnerable: 3.2.0 ... v8.6.0 (277 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modifica…
- CVE-2026-55476MEDIUMCVSS 4.3EG 4.3fixed in 8.6.02026-07-10
vulnerable: 3.2.0 ... v8.5.0 (276 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_admin as a URL path segment without sufficient authorization, allowing an a…
- CVE-2026-55478MEDIUMCVSS 5.4EG 5.4fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but does not authorize access to the referenced license object, allowing a low-privilege user wi…
- CVE-2026-55479MEDIUMCVSS 4.3EG 4.3fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses bu…
- CVE-2026-55481MEDIUMCVSS 4.8EG 4.8fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a …
- CVE-2026-55482MEDIUMCVSS 6.3EG 6.3fixed in 8.4.22026-06-23
vulnerable: 3.2.0 ... v8.4.1 (275 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/BulkAssetsController.php update() to submit company_id directly without Company::getIdForCurrentUser(), allowing assets…
- CVE-2026-55483HIGHCVSS 8.8EG 8.8fixed in 8.6.02026-06-23
vulnerable: 3.2.0 ... v8.5.0 (276 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission can submit the admin permission while creating a user because store() in app/Http/Controllers/Users/UsersController.php s…
- CVE-2026-55515MEDIUMCVSS 5.0EG 5.0fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking acces…
- CVE-2026-55516HIGHCVSS 7.7EG 7.7fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} checks access to the current maintenance record and asset but then fills attacker-controlled fields including asset_id wi…
- CVE-2026-55519MEDIUMCVSS 5.4EG 5.4fixed in 8.4.12026-06-23
vulnerable: 3.2.0 ... v8.4.0 (274 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside the user's ownership or company assignment. The destroy() methods in ap…
- CVE-2026-55542MEDIUMCVSS 4.3EG 4.3fixed in 8.5.12026-06-23
vulnerable: 3.2.0 ... v8.5.0 (276 versions)
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obta…
- CVE-2026-55643HIGHCVSS 8.8EG 8.8fixed in 8.6.32026-08-19
vulnerable: 3.2.0 ... v8.6.2 (279 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUserH…
- CVE-2026-55694MEDIUMCVSS 6.5EG 6.5fixed in 8.6.32026-08-19
vulnerable: 3.2.0 ... v8.6.2 (279 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /api/v1/users/{target_id}/eulas to obtain another user's randomized EULA filename and then download the signed file through /account/stored-eu…
- CVE-2026-55703MEDIUMCVSS 4.3EG 4.3fixed in 8.6.32026-08-19
vulnerable: 3.2.0 ... v8.6.2 (279 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same company without asset or maintenance permission. app/Http/Controlle…
- CVE-2026-55843MEDIUMCVSS 6.5EG 6.5fixed in 8.6.02026-07-10
vulnerable: 3.2.0 ... v8.5.0 (276 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through NormalizePermissionsPayloadAction and PreserveUnauthorizedPrivilegedPermissionsAction in a way t…
- CVE-2026-61807MEDIUMCVSS 6.1EG 6.1fixed in 8.6.22026-08-19
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the table component $name becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-side…
- CVE-2026-62368HIGHCVSS 8.4EG 8.4fixed in 8.7.02026-09-24
vulnerable: 3.2.0 ... v8.6.3 (280 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-tabl…
- CVE-2026-63493HIGHCVSS 8.1EG 8.1fixed in 8.7.02026-09-24
vulnerable: 3.2.0 ... v8.6.3 (280 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-token API flow before completing the account's second-factor challeng…
- CVE-2026-63498MEDIUMCVSS 5.4EG 5.4fixed in 8.7.02026-09-24
vulnerable: 3.2.0 ... v8.6.3 (280 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML and XSLT attachments a…
Check whether snipe/snipe-it is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for snipe/snipe-it CVEs against the assets you own.
Book a Demo →