CSV Formula Injection Vulnerability in Snipe-IT Asset Management
CVE-2026-86742

5.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-86742?

The Snipe-IT asset management tool prior to version 8.7.0 contains a CSV formula injection vulnerability. This flaw arises from the improper handling of free-text fields in the 'unaccepted assets' acceptance report CSV export. An authenticated low-privilege user can manipulate fields to include formula elements that, when exported and opened in spreadsheet applications, can execute arbitrary commands or exfiltrate data. The vulnerability allows an attacker to craft malicious input that is executed as a formula in the context of the end-user's application, leading to significant data risks.

Affected Version(s)

snipe-it 0 < 8.7.0

snipe-it 8.7.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

arpitjain099
snipe
.