Critical CVEs Discovered in Snipe-IT Affecting User Authentication and CSS Injection

Critical CVEs Discovered in Snipe-IT Affecting User Authentication and CSS Injection

First seen 10 Sep 2026, 10:43 UTC Redpacketsecuritygithub.comwww.vulncheck.com 64.5

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities have been identified in Snipe-IT prior to version 8.7.0. CVE-2026-86770 allows attackers to exploit case sensitivity issues during SAML authentication, potentially leading to account takeovers. CVE-2026-86738 involves CSS injection due to improper sanitization, enabling superusers to execute malicious CSS and exfiltrate sensitive data. Organizations using Snipe-IT, especially those with exposed federated login paths or shared superuser accounts, are at high risk. Immediate remediation is necessary, including upgrading to the latest version and reviewing access controls. No active exploitation has been confirmed for either CVE, but both pose significant risks to sensitive data and user accounts.

Key Points: • CVE-2026-86770 enables account takeover via SAML authentication vulnerabilities. • CVE-2026-86738 allows CSS injection through improperly sanitized input fields. • Immediate upgrades to Snipe-IT version 8.7.0 or later are critical for security.

Ask AI about this cluster

Timeline

2026-09-08
CVE-2026-86738 published
Snipe-IT vulnerability allows CSS injection due to improper sanitization, affecting superuser accounts.
Redpacketsecurity
2026-09-09
CVE-2026-86770 published
Snipe-IT vulnerability allows account takeover via SAML authentication due to case sensitivity issues.
Redpacketsecurity
Recent
Organizations urged to upgrade
Snipe-IT users are advised to upgrade to version 8.7.0 to mitigate identified vulnerabilities.
Redpacketsecurity