Snipe-it
This hub aggregates every CVE we track for Snipe-it, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
124
CVEs tracked
2
Critical
30
High
0
In CISA KEV
Severity distribution
MEDIUM88HIGH30LOW4CRITICAL2
Monthly trend
1
2
0
0
0
0
0
1
0
0
0
2
0
2
2
0
0
1
1
4
2
20
7
46
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Snipe-it.
- CVE-2026-88894Snipe-IT before 8.7.2 Authorization Bypass via Predefined Kit Checkout5.4
- CVE-2026-86774Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy6.3
- CVE-2026-86773Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints5.4
- CVE-2026-86772Snipe-IT 8.6.3 Stored XSS via Department Names5.4
- CVE-2026-86771Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num7.6
- CVE-2026-86770Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation8.1
- CVE-2026-86769Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout4.3
- CVE-2026-86768Snipe-IT before 8.7.0 Improper Input Validation via API Checkout5.4
- CVE-2026-86767Snipe-IT before 8.7.0 Cross-Company Read via requested-assets5.0
- CVE-2026-86766Snipe-IT 8.6.3 Race Condition via Consumable Checkout6.5
- CVE-2026-86764Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components6.5
- CVE-2026-86765Snipe-IT 8.6.3 Authorization Bypass via Asset Update Endpoint6.5
- CVE-2026-86763snipe-it 7.0.12 through 8.6.3 Authorization Bypass via Importer3.5
- CVE-2026-86762Snipe-IT before 8.7.0 Authentication Bypass via API Middleware8.1
- CVE-2026-86761snipe-it 8.6.3 before 8.7.0 Authorization Bypass via print endpoints4.3
Product normalization is registry-driven with AI assist and human review. How it works