Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2026-86770 — Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation

Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case var…

snipe-it | Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.3 MEDIUM
CVE-2026-86769 — Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout

Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column inst…

snipe-it | Remote | Misconfiguration
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.4 MEDIUM
CVE-2026-86768 — Snipe-IT before 8.7.0 Improper Input Validation via API Checkout

Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets. Attackers can s…

snipe-it | Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.3 MEDIUM
CVE-2026-86767 — Snipe-IT before 8.7.0 Cross-Company Read via requested-assets

Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.vi…

snipe-it | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-86766 — Snipe-IT 8.6.3 Race Condition via Consumable Checkout

Snipe-IT versions up to and including 8.6.3 contain a race condition (TOCTOU) in the consumable checkout API endpoint (POST /api/v1/consumables/{consumable_id}/checkout). The requested quantity is va…

snipe-it | Remote | Race Condition
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-86765 — Snipe-IT 8.6.3 Authorization Bypass via Asset Update Endpoint

Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset update endpoint. Authenticated users with edit permission but explicitly denied…

snipe-it | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-86764 — Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components

Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only…

snipe-it | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.1 MEDIUM
CVE-2026-86763 — snipe-it 7.0.12 through 8.6.3 Authorization Bypass via Importer

Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewire\Importer, mounted at the imports.index route). The component only checked the…

snipe-it | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.6 HIGH
CVE-2026-86762 — Snipe-IT before 8.7.0 Authentication Bypass via API Middleware

Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php, and deactivating a user does not revoke that user's Passport personal ac…

snipe-it | Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.3 MEDIUM
CVE-2026-86761 — snipe-it 8.6.3 before 8.7.0 Authorization Bypass via print endpoints

snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location vi…

snipe-it | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.4 MEDIUM
CVE-2026-86760 — snipe-it 8.2.0 before 8.7.0 Authentication Bypass via activated flag

Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/Users/UsersController::update(). The single-user edit route assigned the activat…

snipe-it | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-86759 — Snipe-IT before 8.7.0 Missing Authorization via asset-history CSV importer

Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV fi…

snipe-it | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-86758 — Snipe-IT before 8.7.0 License Key Exposure via CSV Export

Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access produc…

snipe-it | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-86757 — Snipe-IT before 8.7.0 Information Disclosure via Custom Fields

Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field values in asset form templates for listbox, textarea, markdown-textarea, and date/datetime picker elements. Authenticated…

snipe-it | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
6.1 MEDIUM
CVE-2026-86756 — Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState

Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs). The endpoint wrote the RelayState POST parameter di…

snipe-it | Remote | Server-Side Request Forgery
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.4 MEDIUM
CVE-2026-86755 — Snipe-IT 4.2.0 through 8.6.3 Permission Bypass via OAuth

Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middlewa…

snipe-it | Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.5 HIGH
CVE-2026-86754 — Snipe-IT before 8.7.0 Authorization Bypass via OAuth Clients

Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated user to register OAuth clients with attacker-controlled redirect URIs. Attac…

snipe-it | Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.3 MEDIUM
CVE-2026-86753 — snipe-it before 8.7.0 Business Logic Bypass via asset_model endpoint

snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint. Authenticated users can bypass administrative restri…

snipe-it | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.4 MEDIUM
CVE-2026-86752 — snipe-it before 8.7.0 Authorization Bypass via Asset Audit Endpoints

snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with…

snipe-it | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.5 HIGH
CVE-2026-86751 — Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Markdown

Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests. Attackers can s…

snipe-it | Remote | Path Traversal
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
Showing 20 of 13921 Results