Authentication Bypass Vulnerability in Snipe-IT by Grokability
CVE-2026-49870

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-49870?

The Snipe-IT asset management system suffers from an authentication vulnerability where the POST /two-factor endpoint lacks rate limiting and lockout mechanisms. This allows an attacker with valid credentials to repeatedly guess TOTP codes without restriction, potentially gaining unauthorized access to user accounts. Furthermore, if two-factor authentication is enabled, an attacker can exploit this weakness to disable the protection without having to reverify the one-time password. The vulnerability has been addressed in version 8.6.1, which introduces necessary safeguards to prevent such unauthorized access.

Affected Version(s)

snipe-it < 8.6.1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.