Server-Side Request Forgery in Snipe-IT by Grokability
CVE-2026-86735
5.9MEDIUM
What is CVE-2026-86735?
Versions of Snipe-IT prior to 8.7.0 are susceptible to a server-side request forgery (SSRF) due to a flaw in the ExternalUrl validation rule. This vulnerability allows attackers with super-admin privileges to configure webhook URLs utilizing NAT64, 6to4, or Teredo transition addresses. By manipulating these addresses, attackers can evade SSRF protections, potentially gaining unauthorized access to internal services or cloud metadata endpoints.
Affected Version(s)
snipe-it 0 < 8.7.0
snipe-it 8.7.0
