Junglewise Threat Intelligence

CVE-2026-86771: Snipe-IT acceptance PDF server-side request forgery via unescaped employee_num

CVE-2026-86771 · Severity: high · CVSS 7.6 · Published 2026-09-09

Technologies: Snipe-It. Vendors: Snipeitapp.

Executive brief

Snipe-IT is an open-source IT asset management system used to track and manage computer hardware and software across organizations. The acceptance PDF generator fails to sanitize the employee_num field, allowing users with routine edit permissions to inject malicious image tags that trigger server-side HTTP requests. When an employee signs an asset acceptance document, an attacker could force the server to connect to internal cloud services, steal credentials, or scan internal infrastructure.

Technical details

The vulnerability is a Server-Side Request Forgery (CWE-918) achieved via HTML injection (CWE-79) in the CheckoutAcceptance::generateAcceptancePdf() function. The employee_num field is concatenated directly into a TCPDF writeHTML() call without HTML escaping, while all other user-supplied fields in the same function are properly escaped via the e() function. TCPDF's writeHTML() parser supports a subset of HTML including img tags with HTTP(S) URIs, which triggers server-side file fetches. An attacker with users.edit permission (granted to HR and help desk roles) can inject an img tag with an arbitrary URL. The payload is triggered when a victim accepts an asset checkout requiring a signature, causing the Snipe-IT server to issue requests to cloud metadata endpoints, internal services, or external targets. The vulnerability is fixed in commit fd7c6b13e9 and released in version 8.7.0.

Affected products

  • Snipe-IT Snipe-IT before 8.7.0

Timeline

  • 2026-08-24: disclosed: GitHub Security Advisory GHSA-73xg-j94v-gjcf published
  • 2026-07-13: patched: Fix committed on develop branch (commit fd7c6b13e9)
  • 2026-09-09: advisory: CVE-2026-86771 assigned and publicly disclosed

References

Related threats