snipe/snipe-it Security Advisories for v8.1.16 (42)
-
[HIGH] Snipe-IT has an Improper Privilege Management issue
PKSA-dysn-9smy-t3nb CVE-2026-55843 GHSA-j5g3-42wp-gqm3
Affected version: <8.6.0
Reported by:
GitHub -
[HIGH] Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update
PKSA-9w68-kyxd-kgh7 CVE-2026-55516 GHSA-575r-357h-fhch
Affected version: <=8.6.1
Reported by:
GitHub -
[MEDIUM] Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint
PKSA-mtr1-kyd4-dpz1 CVE-2026-55515 GHSA-35cr-9hqq-p2mg
Affected version: <=8.6.1
Reported by:
GitHub -
[MEDIUM] Snipe-IT has CSS Injection via `header_color` Setting
PKSA-78g8-kyjb-j6v1 CVE-2026-55481 GHSA-w7qw-5wfv-gwx9
Affected version: <=8.6.1
Reported by:
GitHub -
[MEDIUM] Snipe-IT has incorrect permission for legacy license checkin API
PKSA-j17x-hbvs-1cxn CVE-2026-55479 GHSA-8frh-vhgh-64cf
Affected version: <=8.6.1
Reported by:
GitHub -
[MEDIUM] Snipe-IT has missing object-level authorization in Kits API
PKSA-3nxv-xvdx-984d CVE-2026-55478 GHSA-crv3-j83j-f3r6
Affected version: <=8.6.1
Reported by:
GitHub -
[MEDIUM] Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter
PKSA-3ybt-zv27-1tk1 CVE-2026-55476 GHSA-53jc-27pc-x8r8
Affected version: <8.6.0
Reported by:
GitHub -
[MEDIUM] Snipe-IT's import created_by can be overwritten
PKSA-spdd-pnpq-79f1 CVE-2026-55475 GHSA-5wx7-xq8j-v4qm
Affected version: <=8.6.0
Reported by:
GitHub -
[HIGH] Snipe-IT vulnerable to directory traversal in displaySig
PKSA-b2sw-ngv6-5kt1 CVE-2026-55474 GHSA-c6f4-wj38-m3g3
Affected version: <8.5.0
Reported by:
GitHub -
[MEDIUM] Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation
PKSA-wsms-bsnd-yhwp CVE-2026-55472 GHSA-8w8c-8mx9-52cw
Affected version: <=8.6.1
Reported by:
GitHub -
[LOW] Snipe-IT has a path traversal vulnerability via CSV import `image` field
PKSA-4bks-zvdb-53gs CVE-2026-55469 GHSA-xr9m-gphc-9p63
Affected version: <=8.6.1
Reported by:
GitHub -
[MEDIUM] Snipe-IT vulnerable to stored XSS via inline-served attachment
PKSA-3mmm-zfys-jjqm CVE-2026-55466 GHSA-jhph-5q74-pmfx
Affected version: <=8.6.1
Reported by:
GitHub -
[MEDIUM] Snipe-IT vulnerable to stored XSS via Markdown custom field
PKSA-6ddj-s9z1-gtxr CVE-2026-55464 GHSA-r52f-r9v5-66xr
Affected version: <=8.6.1
Reported by:
GitHub -
[MEDIUM] Snipe-IT has an authorization bypass on print inventory page
PKSA-2vjy-7jj7-vvq3 CVE-2026-55462 GHSA-fc33-6w3q-538h
Affected version: <=8.6.0
Reported by:
GitHub -
[MEDIUM] Snipe-IT has an Open Redirect After User Edit
PKSA-3b5d-jjsk-z4w4 CVE-2026-55461 GHSA-wg2f-x2c2-c4rp
Affected version: <=8.6.1
Reported by:
GitHub -
[HIGH] Snipe-IT has an authorization bypass on bulk editing users
PKSA-n99m-2gcm-8bc6 CVE-2026-55460 GHSA-vgx7-c78r-69w9
Affected version: <=8.6.1
Reported by:
GitHub -
[MEDIUM] Snipe-IT has CSV formula injection in Activity Report export
PKSA-cj32-qmb9-vwgy CVE-2026-55452 GHSA-whrx-mmgr-gpcf
Affected version: <=8.6.1
Reported by:
GitHub -
[MEDIUM] Snipe-IT: Stored DOM XSS via table selected-count IDs
PKSA-9ywr-ywdr-gcrt CVE-2026-61807 GHSA-c8qc-wf67-342w
Affected version: <8.6.2
Reported by:
GitHub -
[MEDIUM] Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET
PKSA-2v9y-4jt3-bxpm CVE-2026-55703 GHSA-r9r3-g9fp-3q4q
Affected version: <8.6.3
Reported by:
GitHub -
[HIGH] Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover
PKSA-9n96-zyz7-nxh9 CVE-2026-55694 GHSA-3hgv-jr5j-cg9x
Affected version: <8.6.3
Reported by:
GitHub -
[HIGH] Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode
PKSA-g91f-rycz-yjcf CVE-2026-55643 GHSA-c6w2-j4wq-mvwg
Affected version: <8.6.3
Reported by:
GitHub -
[HIGH] Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection
PKSA-2tsw-c1yg-xhyc CVE-2026-54329 GHSA-pwpj-p52h-q484
Affected version: <=8.6.1
Reported by:
GitHub -
[LOW] Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL
PKSA-k6ph-vwdz-djyn CVE-2026-55542 GHSA-6mmj-jhqj-6c6q
Affected version: <=8.5.0
Reported by:
GitHub -
[LOW] Snipe-IT has Improper Authorization in File Deletion (IDOR)
PKSA-dfjb-vj14-j26x CVE-2026-55519 GHSA-x667-r589-43m7
Affected version: <=8.4.0
Reported by:
GitHub -
[MEDIUM] Snipe-IT Vulnerable to Privilege Escalation via Missing admin Permission Check in User Creation
PKSA-nhdc-dm5c-gkjd CVE-2026-55483 GHSA-hf68-g98v-wp9g
Affected version: <8.6.0
Reported by:
GitHub -
[MEDIUM] Snipe-IT has Multi-Tenancy Bypass via Bulk Asset Update
PKSA-44m9-kxcv-rmgf CVE-2026-55482 GHSA-33g4-646g-qwmm
Affected version: <=8.4.1
Reported by:
GitHub -
[MEDIUM] Snipe-IT has a 2FA reset privilege bypass
PKSA-xjxm-8vz6-vf8y CVE-2026-50550 GHSA-6x4j-8954-5hxm
Affected version: <8.5.0
Reported by:
GitHub -
[MEDIUM] Snipe-IT Vulnerable to User Account Escalation via CSV Import
PKSA-sr4q-gvr6-k14n CVE-2026-49976 GHSA-p68w-rgmg-3c2v
Affected version: <8.6.0
Reported by:
GitHub -
[MEDIUM] Snipe-IT's TOTP is Brute-Forceable Due to Missing Rate Limiting on `POST /two-factor`
PKSA-35bw-hh2v-5kbx CVE-2026-49870 GHSA-mr8g-2mj4-pcq2
Affected version: <8.6.0
Reported by:
GitHub -
[HIGH] Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
PKSA-czh5-xdx3-8gjh CVE-2026-48507 GHSA-6f75-x745-xcpr
Affected version: <8.6.0
Reported by:
GitHub -
[MEDIUM] Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
PKSA-7srb-sjc8-3k98 CVE-2026-48493 GHSA-52fw-7fw2-fmv5
Affected version: <8.6.0
Reported by:
GitHub -
[MEDIUM] Snipe-IT's selectlist visibility is too permissive
PKSA-bd8t-dph3-gby8 CVE-2026-48492 GHSA-f3c5-6cw8-fg57
Affected version: <8.5.1
Reported by:
GitHub -
[MEDIUM] Snipe-IT has an open redirect vulnerability
PKSA-rnj3-1mvy-45m9 CVE-2026-44833 GHSA-mghp-5cq4-v6mg
Affected version: <8.4.1
Reported by:
GitHub -
[CRITICAL] Snipe-IT has insecure permissions in file uploads
PKSA-p5z5-yvbr-44mr CVE-2026-37709 GHSA-xg82-2hrv-hf64
Affected version: <8.4.1
Reported by:
GitHub -
[HIGH] Snipe-IT has Privilege Escalation via API Permissions Assignment
PKSA-3w8f-xykp-s5ps CVE-2026-44832 GHSA-hq28-crg7-95pr
Affected version: <8.4.1
Reported by:
GitHub -
[MEDIUM] Snipe-IT has Stored XSS via Component Checkout Notes (v8.4.0)
PKSA-t5t8-ptsk-b8c5 CVE-2026-44831 GHSA-r42m-953q-6vjx
Affected version: <8.4.1
Reported by:
GitHub -
[HIGH] Snipe-IT has sensitive user attributes related to account privileges that are insufficiently protected against mass assignment
PKSA-b19f-d499-7h75 CVE-2025-15602 GHSA-5448-v74m-7mv7
Affected version: <8.3.7
Reported by:
GitHub -
[MEDIUM] Snipe-IT allows stored XSS via the Locations "Country" field
PKSA-wtqq-tf96-nxmc CVE-2025-65622 GHSA-4g25-wj72-chxg
Affected version: <8.3.4
Reported by:
GitHub -
[MEDIUM] Snipe-IT is vulnerable to stored cross-site scripting
PKSA-czzq-6v8k-876d CVE-2025-65621 GHSA-fww5-m9wc-jcjc
Affected version: <8.3.4
Reported by:
GitHub -
[MEDIUM] Snipe-IT has Cross-site Scripting vulnerability in CSV import workflow
PKSA-c9tc-ctjb-ht9h CVE-2025-64027 GHSA-8x9v-8qgj-945x
Affected version: <=8.3.4
Reported by:
GitHub -
[MEDIUM] Snipe-IT allows unsafe deserialization
PKSA-xzw3-k89w-sm61 CVE-2025-59713 GHSA-phwj-fgch-xvrj
Affected version: <8.1.18
Reported by:
GitHub -
[MEDIUM] Snipe-IT allows XSS
PKSA-hsvj-t2cd-6x2t CVE-2025-59712 GHSA-c9wp-pr7f-hfqm
Affected version: <8.1.18
Reported by:
GitHub