CVE-2026-86734
Analyzed Analyzed - Analysis Complete

Snipe-IT Note Field Length Validation Bypass Leads to DoS

Vulnerability report for CVE-2026-86734, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: VulnCheck

Description

Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{acceptance} endpoint, allowing authenticated users to submit unbounded input that reaches synchronous CommonMark rendering. Attackers can submit large note values to exhaust PHP worker CPU and cause denial of service through resource exhaustion in the markdown parsing pipeline.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
snipeitapp snipe-it to 8.7.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial-of-service (DoS) vulnerability in Snipe-IT versions before 8.7.1. Authenticated users can submit unbounded input in the note field of the POST /account/accept/{acceptance} endpoint. The note is processed synchronously via CommonMark rendering, consuming excessive CPU resources and causing a denial of service through resource exhaustion.

Detection Guidance

Monitor CPU usage spikes during markdown rendering operations. Check Snipe-IT logs for unusually large note submissions in the POST /account/accept/{acceptance} endpoint. Use network traffic analysis to detect excessive data transfers to this endpoint.

Impact Analysis

An attacker with access can cause CPU exhaustion on the server by submitting large notes, leading to degraded performance or complete unavailability of the Snipe-IT application. This disrupts normal operations and may affect other services relying on the same server resources.

Compliance Impact

This vulnerability primarily impacts availability, which is a key aspect of compliance for GDPR and HIPAA. Downtime could lead to disruptions in data access or processing, potentially violating availability requirements. However, no direct confidentiality or integrity risks are mentioned.

Mitigation Strategies

Upgrade Snipe-IT to version 8.7.1 or later. Update the CommonMark library to version 2.9.0 or higher. Implement server-side validation to limit note field length to 1000 characters. Switch to a non-synchronous queue driver if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86734. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart