Vendor
Arbitrary Command Execution in Snipe-IT Backup Restoration
1 rule 14 TTPs 1 CVESnipe-IT versions prior to 8.7.0 are vulnerable to OS command injection when a superadministrator restores a crafted backup archive, allowing arbitrary command execution via the MySQL client.
Broken Access Control in Snipe-IT Asset Maintenance API
2 rules 2 TTPs 1 CVEAn authenticated user in a multi-company Snipe-IT deployment can exploit an authorization flaw in the asset maintenance update API to re-parent records to assets owned by other companies, breaking tenant isolation.
Snipe-IT Information Disclosure and IDOR Vulnerability
1 rule 1 TTP 1 CVEAn authenticated attacker can exploit an information disclosure and IDOR vulnerability (CVE-2026-55694) in Snipe-IT to leak and download confidential, restricted EULA documents belonging to other users.
Multiple Vulnerabilities in Snipe-IT Allow for Code Execution and Privilege Escalation
2 rules 2 TTPsMultiple vulnerabilities in Snipe-IT could allow an attacker to perform cross-site scripting attacks, redirect users to malicious websites, gain administrator rights, or execute arbitrary code.