snipe/snipe-it
Packagist78 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting snipe/snipe-itpage 2 of 2
- CVE-2026-49976MEDIUMCVSS 6.5EG 6.5✓ Fixed in 8.6.02026-06-23
vulnerable: 3.2.0 ... v8.5.0 (276 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update mode to overwrite the email address of a non-admin user and then request a password reset to take over that account. ap…
- CVE-2026-50550MEDIUMCVSS 5.8EG 5.8✓ Fixed in 8.5.02026-06-23
vulnerable: 3.2.0 ... v8.4.1 (275 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmin's two-factor authentication through app/Http/Controllers/Api/UsersController.php postTwoFactorReset(). The endpoint a…
- CVE-2026-54329HIGHCVSS 7.7EG 7.7✓ Fixed in 8.6.22026-06-23
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in …
- CVE-2026-55452HIGHCVSS 7.3EG 7.3✓ Fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes that value to the Activity Report CSV without formula escapin…
- CVE-2026-55460HIGHCVSS 7.1EG 7.1✓ Fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and users.edit but without users.delete can directly POST to /users/bulksave with delete_user=1 because BulkUsersController:…
- CVE-2026-55461MEDIUMCVSS 6.1EG 6.1✓ Fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the attacker-controlled Referer header into Laravel’s intended URL session value and later uses redirect()->intended(...)…
- CVE-2026-55462MEDIUMCVSS 4.3EG 4.3✓ Fixed in 8.6.12026-07-10
vulnerable: 3.2.0 ... v8.6.0 (277 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing an…
- CVE-2026-55464MEDIUMCVSS 5.4EG 5.4✓ Fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user with assets.edit permission to place a malicious link in a markdo…
- CVE-2026-55466HIGHCVSS 8.7EG 8.7✓ Fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml and UploadedFilesController serves attachments inline without using StorageHelper::allowSa…
- CVE-2026-55469MEDIUMCVSS 6.5EG 6.5✓ Fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path traversal string in an asset image field through CSV import and then trigger image deletion…
- CVE-2026-55472MEDIUMCVSS 4.3EG 4.3✓ Fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not …
- CVE-2026-55474MEDIUMCVSS 6.5EG 6.5✓ Fixed in 8.5.02026-07-10
vulnerable: 3.2.0 ... v8.4.1 (275 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to t…
- CVE-2026-55475MEDIUMCVSS 5.7EG 5.7✓ Fixed in 8.6.12026-07-10
vulnerable: 3.2.0 ... v8.6.0 (277 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modifica…
- CVE-2026-55476MEDIUMCVSS 4.3EG 4.3✓ Fixed in 8.6.02026-07-10
vulnerable: 3.2.0 ... v8.5.0 (276 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_admin as a URL path segment without sufficient authorization, allowing an a…
- CVE-2026-55478MEDIUMCVSS 5.4EG 5.4✓ Fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but does not authorize access to the referenced license object, allowing a low-privilege user wi…
- CVE-2026-55479MEDIUMCVSS 4.3EG 4.3✓ Fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses bu…
- CVE-2026-55481MEDIUMCVSS 4.8EG 4.8✓ Fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a …
- CVE-2026-55482MEDIUMCVSS 6.3EG 6.3✓ Fixed in 8.4.22026-06-23
vulnerable: 3.2.0 ... v8.4.1 (275 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/BulkAssetsController.php update() to submit company_id directly without Company::getIdForCurrentUser(), allowing assets…
- CVE-2026-55483MEDIUMCVSS 4.9EG 4.9✓ Fixed in 8.6.02026-06-23
vulnerable: 3.2.0 ... v8.5.0 (276 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission can submit the admin permission while creating a user because store() in app/Http/Controllers/Users/UsersController.php s…
- CVE-2026-55515MEDIUMCVSS 5.0EG 5.0✓ Fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking acces…
- CVE-2026-55516HIGHCVSS 7.7EG 7.7✓ Fixed in 8.6.22026-07-10
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} checks access to the current maintenance record and asset but then fills attacker-controlled fields including asset_id wi…
- CVE-2026-55519MEDIUMCVSS 5.4EG 5.4✓ Fixed in 8.4.12026-06-23
vulnerable: 3.2.0 ... v8.4.0 (274 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside the user's ownership or company assignment. The destroy() methods in ap…
- CVE-2026-55542MEDIUMCVSS 4.3EG 4.3✓ Fixed in 8.5.12026-06-23
vulnerable: 3.2.0 ... v8.5.0 (276 versions)
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obta…
- CVE-2026-55643HIGHCVSS 7.6EG 7.6✓ Fixed in 8.6.32026-08-19
vulnerable: 3.2.0 ... v8.6.2 (279 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUserH…
- CVE-2026-55694HIGHCVSS 7.1EG 7.1✓ Fixed in 8.6.32026-08-19
vulnerable: 3.2.0 ... v8.6.2 (279 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /api/v1/users/{target_id}/eulas to obtain another user's randomized EULA filename and then download the signed file through /account/stored-eu…
- CVE-2026-55703MEDIUMCVSS 4.3EG 4.3✓ Fixed in 8.6.32026-08-19
vulnerable: 3.2.0 ... v8.6.2 (279 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same company without asset or maintenance permission. app/Http/Controlle…
- CVE-2026-55843MEDIUMCVSS 6.5EG 6.5✓ Fixed in 8.6.02026-07-10
vulnerable: 3.2.0 ... v8.5.0 (276 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through NormalizePermissionsPayloadAction and PreserveUnauthorizedPrivilegedPermissionsAction in a way t…
- CVE-2026-61807MEDIUMCVSS 6.3EG 6.3✓ Fixed in 8.6.22026-08-19
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the table component $name becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-side…
Check whether snipe/snipe-it is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for snipe/snipe-it CVEs against the assets you own.
Start Free Scan →