Server-Side Request Forgery in Snipe-IT by Grokability
CVE-2026-86771

8.3HIGH

Key Information:

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-86771?

Earlier versions of Snipe-IT (prior to 8.7.0) possess a vulnerability that allows attackers with 'users.edit' permission to execute server-side requests. This vulnerability arises from inadequate HTML-escaping of the 'employee_num' field in the PDF generator, enabling malicious users to inject image tags containing harmful HTTP(S) URLs. Once a victim interacts with the acceptance of an asset, these crafted URLs can trigger requests to internal services or external endpoints, potentially exposing sensitive data to unauthorized access.

Affected Version(s)

snipe-it 8.6.3 < 8.7.0

snipe-it 8.7.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ya3raj
.