Skip to content
Threat Feed

Tag

Asset-Management

4 briefs RSS
high advisory

Arbitrary Command Execution in Snipe-IT Backup Restoration

Snipe-IT versions prior to 8.7.0 are vulnerable to OS command injection when a superadministrator restores a crafted backup archive, allowing arbitrary command execution via the MySQL client.

Snipe-IT +1 remote-code-execution cve vulnerability web-vulnerability css-injection account-takeover cve-2026-86751 ssrf +8
1r 14t 1c updated
high advisory

Broken Access Control in Snipe-IT Asset Maintenance API

An authenticated user in a multi-company Snipe-IT deployment can exploit an authorization flaw in the asset maintenance update API to re-parent records to assets owned by other companies, breaking tenant isolation.

Snipe-IT +2 web-application privilege-escalation multi-tenant web-application-vulnerability path-traversal cve-2026-55474 authorization-bypass asset-management
2r 2t 1c
high advisory

Pimcore WebDAV Asset MOVE Missing Authorization Vulnerability

Pimcore's WebDAV asset endpoint exposes a `MOVE` operation without authentication, allowing unauthenticated remote attackers to delete assets if they know two existing asset paths in the same directory; Authenticated low-privileged users may also be able to perform unauthorized asset move or overwrite operations because the move path does not enforce `rename`, `delete`, `create`, or `publish` permissions, leading to data loss, content integrity loss, and service disruption.

pimcore/pimcore webdav asset-management missing-authorization pimcore
2r 2t
critical advisory

Snipe-IT File Upload Vulnerability Leads to Remote Code Execution (CVE-2026-37709)

Snipe-IT versions prior to 8.4.1 are vulnerable to remote code execution due to insecure permissions on file uploads, where an attacker can upload arbitrary files and execute code on the server.

snipe-it remote code execution file upload insecure permissions asset management CVE-2026-37709
2r 1t 1c