Junglewise Threat Intelligence

CVE-2026-86742: Snipe-IT formula injection in asset acceptance report CSV export

CVE-2026-86742 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Snipeitapp Snipe-It. Vendors: Snipeitapp.

Executive brief

Snipe-IT is an asset management platform used to track hardware and equipment inventory. A vulnerability in the CSV export feature of the unaccepted assets acceptance report allows attackers to inject malicious formulas into exported files. When a user with reporting permissions downloads and opens the CSV in Excel, LibreOffice Calc, or Google Sheets, the formulas can be executed to steal data or run arbitrary commands on the user's workstation.

Technical details

The vulnerability is a CSV formula injection (CWE-1236) in the postAssetAcceptanceReport() method of ReportsController.php. The CSV export fails to neutralize formula prefix characters (=, +, -, @, tab, CR) despite importing and using the League\Csv\EscapeFormula helper in six other exports in the same controller. An authenticated user with ordinary create/edit rights on asset records can inject formulas into free-text fields (asset name/tag, company name, category, model, or assignee display name) that appear in the report. When a user with reports.view privileges requests the CSV export and opens it in a spreadsheet application, the formulas are evaluated in the context of the victim's workstation, enabling data exfiltration via HYPERLINK/WEBSERVICE or DDE command execution on legacy Windows Excel. The fix applies the same EscapeFormula escaping pattern already used by sibling exports, gated on the config('app.escape_formulas') setting. This vulnerability was patched in version 8.7.0.

Affected products

  • Grokability Snipe-IT through 8.6.3

Timeline

  • 2026-09-09: disclosed
  • 2026: patched: Fixed in version 8.7.0 (commit 2fc38b1)

References

Related threats