Server-Side Request Forgery in Snipe-IT by Grokability
CVE-2026-86735

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-86735?

Versions of Snipe-IT prior to 8.7.0 are susceptible to a server-side request forgery (SSRF) due to a flaw in the ExternalUrl validation rule. This vulnerability allows attackers with super-admin privileges to configure webhook URLs utilizing NAT64, 6to4, or Teredo transition addresses. By manipulating these addresses, attackers can evade SSRF protections, potentially gaining unauthorized access to internal services or cloud metadata endpoints.

Affected Version(s)

snipe-it 0 < 8.7.0

snipe-it 8.7.0

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tonghuaroot
snipe
.