Redpacketsecurity
Critical CVEs Discovered in Snipe-IT Affecting User Authentication and CSS Injection
Article Content
Two critical vulnerabilities have been identified in Snipe-IT prior to version 8.7.0. CVE-2026-86770 allows attackers to exploit case sensitivity issues during SAML authentication, potentially leading to account takeovers. CVE-2026-86738 involves CSS injection due to improper sanitization, enabling superusers to execute malicious CSS and exfiltrate sensitive data. Organizations using Snipe-IT, especially those with exposed federated login paths or shared superuser accounts, are at high risk. Immediate remediation is necessary, including upgrading to the latest version and reviewing access controls. No active exploitation has been confirmed for either CVE, but both pose significant risks to sensitive data and user accounts.
Key Points: • CVE-2026-86770 enables account takeover via SAML authentication vulnerabilities. • CVE-2026-86738 allows CSS injection through improperly sanitized input fields. • Immediate upgrades to Snipe-IT version 8.7.0 or later are critical for security.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.