Cross-Site Scripting in Snipe-IT IT Asset Management System
CVE-2026-62368

8.1HIGH

Key Information:

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-62368?

In versions of Snipe-IT before 8.7.0, a security flaw exists where a user with permission to create custom fields can input unvalidated markup into the CustomField.name. This unescaped data is then utilized as a bootstrap-table header title. When accessed by another user, this leads to the execution of the stored markup within their session, potentially exposing sensitive same-origin data. Furthermore, such exploits can enable an attacker to execute actions as the victim user, facilitating unauthorized privilege escalation, especially when a superuser views the vulnerable asset-list page.

Affected Version(s)

snipe-it < 8.7.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.