Snipe-IT IT Asset Management System Vulnerability
CVE-2026-63493

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-63493?

The Snipe-IT IT asset management system has a significant vulnerability that allows an attacker with password-authenticated access and self.api permission to bypass the second-factor authentication challenge when accessing the personal-access-token API flow. This occurs because the CheckForTwoFactor enforcement applies to the web middleware group, but not to the API middleware group. As a result, the attacker can obtain a persistent API token that grants them the ability to read and modify resources within the system, including sensitive user permissions. For administrators, this can lead to further exploitation by permitting access to the users/two_factor_reset endpoint, enabling the attacker to reset the second-factor authentication for administrative accounts. This flaw poses a severe risk as it provides extensive API access without requiring a valid web session, effectively allowing attackers to take over legitimate user accounts without detection. Users are encouraged to upgrade to version 8.7.0 or later to mitigate this risk.

Affected Version(s)

snipe-it < 8.7.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.