CVE-2026-86735
Analyzed Analyzed - Analysis Complete

Server-Side Request Forgery in Snipe-IT Before 8.7.0 via IPv6 Transition Addresses

Vulnerability report for CVE-2026-86735, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: VulnCheck

Description

snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets. Attackers with super-admin privileges can configure webhook URLs using NAT64, 6to4, or Teredo transition addresses to bypass SSRF guards and access internal services or cloud metadata endpoints.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
snipeitapp snipe-it to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Snipe-IT versions before 8.7.0. It involves a bypass of the SSRF guard in the ExternalUrl validation rule using IPv6 transition addresses like NAT64, 6to4, or Teredo. These addresses encode private IPv4 targets, allowing attackers with super-admin privileges to access internal services or cloud metadata endpoints.

Detection Guidance

To detect this vulnerability, check if your Snipe-IT instance is running a version before 8.7.0. Use commands like 'curl -s https://your-snipe-it-domain.com/ | grep "Snipe-IT"' to identify the version. Inspect webhook configurations for IPv6 transition addresses (NAT64, 6to4, Teredo) in URLs or domains.

Impact Analysis

An attacker could exploit this to access sensitive internal services or cloud metadata (e.g., AWS/GCP/Azure IMDS). This could lead to data breaches, unauthorized access to internal infrastructure, or port scanning of internal systems. The attack requires high privileges and specific conditions.

Mitigation Strategies

Upgrade Snipe-IT to version 8.7.0 or later immediately. Review and remove any webhook URLs using IPv6 transition addresses. Implement stricter validation for ExternalUrl rules to reject NAT64, 6to4, and Teredo addresses.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86735. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart