Authentication Bypass Vulnerability in Snipe-IT by Grokability
CVE-2026-49870
5.9MEDIUM
What is CVE-2026-49870?
The Snipe-IT asset management system suffers from an authentication vulnerability where the POST /two-factor endpoint lacks rate limiting and lockout mechanisms. This allows an attacker with valid credentials to repeatedly guess TOTP codes without restriction, potentially gaining unauthorized access to user accounts. Furthermore, if two-factor authentication is enabled, an attacker can exploit this weakness to disable the protection without having to reverify the one-time password. The vulnerability has been addressed in version 8.6.1, which introduces necessary safeguards to prevent such unauthorized access.
Affected Version(s)
snipe-it < 8.6.1
