Arbitrary File Read and SSRF in Snipe-IT by Snipe-IT
CVE-2026-86741

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-86741?

Snipe-IT versions prior to 8.7.0 are vulnerable due to insufficient sanitization of the category EULA text field in checkout confirmation emails. This allows attackers with low-privilege permissions to inject markdown image syntax or HTML img tags that reference local files or remote URLs. The email system's auto-embed feature processes these references server-side, potentially resulting in the leakage of sensitive information such as .env credentials and enabling server-side request forgery (SSRF) attacks.

Affected Version(s)

snipe-it 0 < 8.7.0

snipe-it 8.7.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

W1nterFr3ak
snipe
christopherfi-dev
.