Junglewise Threat Intelligence

CVE-2026-86734: Snipe-IT input validation bypass in acceptance endpoint

CVE-2026-86734 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: Snipe-It. Vendors: Snipeitapp.

Executive brief

Snipe-IT is an open-source asset management system used by organizations to track IT equipment and hardware. A flaw in the asset acceptance workflow allows authenticated users to submit extremely long notes that trigger excessive CPU consumption during markdown processing, causing the web application to become unresponsive and denying service to legitimate users.

Technical details

The vulnerability is an input validation bypass (CWE-1284) combined with uncontrolled resource consumption (CWE-400) in the POST /account/accept/{acceptance} endpoint. The note field lacks server-side length validation before being persisted and passed to the AcceptanceItemDeclinedNotification, where it undergoes synchronous markdown rendering via league/commonmark 2.8.2. By default, Snipe-IT uses a synchronous queue driver, causing parser CPU work to block the request cycle. An authenticated attacker with a pending checkout acceptance can submit notes exceeding 80,000 bytes, causing 2.6+ seconds of CPU exhaustion per request. The fix (v8.7.1) upgrades league/commonmark to 2.9.0+ and adds server-side validation (max:1000) on the note field before persistence or notification.

Affected products

  • Snipe-IT Snipe-IT before 8.7.1

Timeline

  • 2026-08-24: disclosed: GHSA-4vcv-fc5x-jjwv published on GitHub Security Advisories
  • 2026-08-11: patched: Fix committed (66770cfe); v8.7.1 released
  • 2026-09-08: advisory: CVE-2026-86734 published on NVD

References

Related threats