Technology · Snipeitapp
Snipeitapp Snipe-It vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 89 vulnerabilities in Snipeitapp Snipe-It: 3 in the last 7 days and 73 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-63498, was published on 24 September 2026.
- Last 7 days
- 3
- Last 90 days
- 73
- Critical, all time
- 1
- Exploited in the wild
- 0
About Snipeitapp Snipe-It
An open-source IT asset management system built on the Laravel framework.
Latest Snipeitapp Snipe-It vulnerabilities
- CVE-2026-63498: Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET…highCVSS 8.7EPSS 0.2%
- CVE-2026-63493: Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with…highCVSS 7.5EPSS 0.3%
- CVE-2026-62368: Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can…highCVSS 8.1EPSS 0.3%
- CVE-2026-88894: Snipe-IT predefined kit checkout FMCS tenant isolation bypassmediumCVSS 5.4EPSS 0.3%
- CVE-2026-86774: Snipe-IT broken access control in Asset Model file attachmentsmediumCVSS 6.3EPSS 0.3%
- CVE-2026-86773: Snipe-IT broken access control in Predefined Kit endpointsmediumCVSS 5.4EPSS 0.3%
- CVE-2026-86772: Snipe-IT stored cross-site scripting in department namesmediumCVSS 5.4EPSS 0.3%
- CVE-2026-86771: Snipe-IT acceptance PDF server-side request forgery via unescaped employee_numhighCVSS 7.6EPSS 0.3%
- CVE-2026-86770: Snipe-IT authentication bypass in SAML username collationhighCVSS 8.1EPSS 0.6%
- CVE-2026-86769: Snipe-IT improper ownership management in consumables checkout APImediumCVSS 4.3EPSS 0.3%
- CVE-2026-86768: Snipe-IT API checkout endpoints improper input validationmediumCVSS 5.4EPSS 0.4%
- CVE-2026-86767: Snipe-IT unauthorized cross-company read in requested assetsmediumCVSS 5EPSS 0.3%
- CVE-2026-86766: Snipe-IT consumable checkout race conditionmediumCVSS 6.5EPSS 0.4%
- CVE-2026-86765: Snipe-IT authorization bypass in asset update endpointmediumCVSS 6.5EPSS 0.4%
- CVE-2026-86764: Snipe-IT permission bypass in assigned components endpointmediumCVSS 6.5EPSS 0.4%
- CVE-2026-86763: Snipe-IT Livewire importer authorization bypasslowCVSS 3.5EPSS 0.3%
- CVE-2026-86762: Snipe-IT authentication bypass via deactivated user API tokenshighCVSS 8.1EPSS 0.5%
- CVE-2026-86761: Snipe-IT authorization bypass in location print endpointsmediumCVSS 4.3EPSS 0.4%
- CVE-2026-86760: Snipe-IT authorization bypass in user account activation togglemediumCVSS 5.4EPSS 0.4%
- CVE-2026-86759: Snipe-IT missing authorization in asset-history CSV importerhighCVSS 7.1EPSS 0.4%
- CVE-2026-86758: Snipe-IT authorization bypass in license key exportmediumCVSS 6.5EPSS 0.4%
- CVE-2026-86757: Snipe-IT authorization bypass in encrypted custom field form renderingmediumCVSS 6.5EPSS 0.4%
- CVE-2026-86756: Snipe-IT open redirect in SAML RelayState parametermediumCVSS 6.1EPSS 0.3%
- CVE-2026-86755: Snipe-IT permission bypass in Passport personal-access-token routesmediumCVSS 5.4EPSS 0.3%
- CVE-2026-86754: Snipe-IT authorization bypass in OAuth client managementhighCVSS 7.3EPSS 0.3%
Most severe Snipeitapp Snipe-It vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-37709: Grokability Snipe-IT insecure permissions in UploadedFilesControllercriticalCVSS 9.8
- CVE-2022-23064: Snipe-IT host header injection in password resethighCVSS 8.8EPSS 1.3%
- CVE-2026-85617: snipe-it authorization bypass in bulk deletehighCVSS 8.8EPSS 0.5%
- CVE-2026-44832: Grokability Snipe-IT privilege escalation in Users APIhighCVSS 8.8EPSS 0.0%
- CVE-2026-86738: Snipe-IT CSS injection in custom CSS fieldhighCVSS 8.7EPSS 0.5%
- CVE-2026-55466: Grokability Snipe-IT stored XSS in asset attachmentshighCVSS 8.7EPSS 0.4%
- CVE-2026-63498: Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET…highCVSS 8.7EPSS 0.2%
- CVE-2026-85616: Snipe-IT authorization bypass in checkout-acceptance reporthighCVSS 8.5EPSS 0.4%
- CVE-2026-86751: Snipe-IT markdown image injection in mail notificationshighCVSS 8.5EPSS 0.4%
- CVE-2026-86741: Snipe-IT arbitrary file read and SSRF via category EULAhighCVSS 8.5EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 20 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 4 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 3 | 0 | |
| 7 Sep 2026 | 43 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 3 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/snipe-it.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Snipeitapp Snipe-It vulnerabilities", https://junglewise.ai/threats/technologies/snipe-it, 26 September 2026.