Description
Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for users without departments.view permission. Users with departments.edit permission can inject malicious scripts into department names that execute in the browsers of all department members when they load their My Assets page.
Published: 2026-09-09
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

Snipe‑IT before version 8.7.0 contains a stored cross‑site scripting flaw in DepartmentPresenter::formattedNameLink(). Department names are output unescaped in a fallback branch for users lacking departments.view permission. Users with departments.edit permission can inject arbitrary JavaScript into a department name. When any department member opens their My Assets page, the malicious script executes in the victim’s browser, potentially stealing session cookies, hijacking the user session, defacing the page, or redirecting to phishing sites. The impact is the compromise of confidentiality and integrity of user data and the ability to perform client‑side attacks against end users.

Affected Systems

The affected product is Snipe‑IT by grokability. All releases before 8.7.0, including version 8.6.3, are vulnerable. The flaw arises in the department handling component and affects all users who can edit a department. If a database contains a crafted department name, any user who views the department’s assets will be exposed.

Risk and Exploitability

The CVSS score of 5.1 marks the vulnerability as moderate, and the EPSS score is not available. It is not listed in the CISA KEV catalog. Exploitation requires the attacker to have permissions to edit a department, which typically implies an admin or privileged account. If the attacker has such access, the flaw can be leveraged against all members of the department when they access their asset lists. Because the impact is client‑side code execution and the attacker does not need to compromise the server, the risk is contained to the affected user base but could be abused for phishing or credential theft. Overall, the urgency of applying a fix is moderate but recommended as soon as possible.

Generated by OpenCVE AI on September 9, 2026 at 15:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to version 8.7.0 or later, which removes the unescaped rendering of department names.
  • Restrict the departments.edit permission to only authorized administrators to reduce the attack surface.
  • If an upgrade is not immediately possible, manually edit the affected department names in the database or via the UI to remove any malicious input and ensure they are sanitized before display.

Generated by OpenCVE AI on September 9, 2026 at 15:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for users without departments.view permission. Users with departments.edit permission can inject malicious scripts into department names that execute in the browsers of all department members when they load their My Assets page.
Title Snipe-IT 8.6.3 Stored XSS via Department Names
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-79
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T14:57:08.509Z

Reserved: 2026-09-08T11:35:02.617Z

Link: CVE-2026-86772

cve-icon Vulnrichment

Updated: 2026-09-10T14:18:32.579Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:27.890

Modified: 2026-09-16T20:28:56.910

Link: CVE-2026-86772

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')