snipe/snipe-it
Packagist57 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting snipe/snipe-itpage 2 of 2
- CVE-2026-49976MEDIUMCVSS 6.5EG 6.5✓ Fixed in 8.6.02026-06-23
vulnerable: 3.2.0 ... v8.5.0 (276 versions)
Snipe-IT Vulnerable to User Account Escalation via CSV Import ### Impact The CSV user import in update mode bypasses user-edit authorization. A user with only the `import` permission can overwrite any non-admin user's email by uploading a…
- CVE-2026-50550MEDIUMCVSS 5.8EG 5.8✓ Fixed in 8.5.02026-06-23
vulnerable: 3.2.0 ... v8.4.1 (275 versions)
Snipe-IT has a 2FA reset privilege bypass ### Impact A user who can edit other users could reset a superadmin's 2FA. ### Patches Patched in 8.5.0
- CVE-2026-54329HIGHCVSS 7.7EG 7.7✓ Fixed in 8.6.22026-06-23
vulnerable: 3.2.0 ... v8.6.1 (278 versions)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in …
- CVE-2026-55482MEDIUMCVSS 6.3EG 6.3✓ Fixed in 8.4.22026-06-23
vulnerable: 3.2.0 ... v8.4.1 (275 versions)
Snipe-IT has Multi-Tenancy Bypass via Bulk Asset Update ### Impact The `BulkAssetsController::update()` method accepts `company_id` directly from user input without calling `Company::getIdForCurrentUser()`, the standard company-scoping fu…
- CVE-2026-55483MEDIUMEG 0.0✓ Fixed in 8.6.02026-06-23
vulnerable: 3.2.0 ... v8.5.0 (276 versions)
Snipe-IT Vulnerable to Privilege Escalation via Missing admin Permission Check in User Creation ### Impact The `store()` method in both the web and API `UsersController` only strips the superuser permission when a non-superuser creates a …
- CVE-2026-55519LOWEG 0.0✓ Fixed in 8.4.12026-06-23
vulnerable: 3.2.0 ... v8.4.0 (274 versions)
Snipe-IT has Improper Authorization in File Deletion (IDOR) ### Impact A vulnerability was identified in Snipe-IT v8.4.0 (build 21280-g91a95dbc6) that allows any authenticated user with generic asset edit permissions to delete files attac…
- CVE-2026-55542MEDIUMCVSS 4.3EG 4.3✓ Fixed in 8.5.12026-06-23
vulnerable: 3.2.0 ... v8.5.0 (276 versions)
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obta…
Check whether snipe/snipe-it is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for snipe/snipe-it CVEs against the assets you own.
Start Free Scan →