Cross-Site Scripting in Snipe-IT IT Asset Management System
CVE-2026-62368
8.1HIGH
What is CVE-2026-62368?
In versions of Snipe-IT before 8.7.0, a security flaw exists where a user with permission to create custom fields can input unvalidated markup into the CustomField.name. This unescaped data is then utilized as a bootstrap-table header title. When accessed by another user, this leads to the execution of the stored markup within their session, potentially exposing sensitive same-origin data. Furthermore, such exploits can enable an attacker to execute actions as the victim user, facilitating unauthorized privilege escalation, especially when a superuser views the vulnerable asset-list page.
Affected Version(s)
snipe-it < 8.7.0
