Skip to content
Threat Feed

Vendor

Snipe-IT

4 briefs RSS
high advisory

Arbitrary Command Execution in Snipe-IT Backup Restoration

Snipe-IT versions prior to 8.7.0 are vulnerable to OS command injection when a superadministrator restores a crafted backup archive, allowing arbitrary command execution via the MySQL client.

Snipe-IT +1 remote-code-execution cve vulnerability web-vulnerability css-injection account-takeover cve-2026-86751 ssrf +8
1r 14t 1c updated
high advisory

Broken Access Control in Snipe-IT Asset Maintenance API

An authenticated user in a multi-company Snipe-IT deployment can exploit an authorization flaw in the asset maintenance update API to re-parent records to assets owned by other companies, breaking tenant isolation.

Snipe-IT +2 web-application privilege-escalation multi-tenant web-application-vulnerability path-traversal cve-2026-55474 authorization-bypass asset-management
2r 2t 1c
high advisory

Snipe-IT Information Disclosure and IDOR Vulnerability

An authenticated attacker can exploit an information disclosure and IDOR vulnerability (CVE-2026-55694) in Snipe-IT to leak and download confidential, restricted EULA documents belonging to other users.

Snipe-IT
1r 1t 1c
critical threat

Multiple Vulnerabilities in Snipe-IT Allow for Code Execution and Privilege Escalation

Multiple vulnerabilities in Snipe-IT could allow an attacker to perform cross-site scripting attacks, redirect users to malicious websites, gain administrator rights, or execute arbitrary code.

exploited Snipe-IT xss code execution
2r 2t