CVE-2026-86738
Analyzed Analyzed - Analysis Complete

CSS Injection in Snipe-IT Before 8.7.0

Vulnerability report for CVE-2026-86738, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: VulnCheck

Description

Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using @import and url() references to exfiltrate CSRF tokens from other superusers via attribute-selector rules, enabling account takeover.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
snipeitapp snipe-it From 3.0.0 (inc) to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86738 is a CSS injection vulnerability in Snipe-IT versions before 8.7.0. It occurs due to incomplete sanitization in the Custom CSS field, allowing HTML encoding to be reversed for certain characters. This enables superusers to inject malicious CSS payloads using @import or url() references that can exfiltrate CSRF tokens from other superusers via attribute selectors.

Detection Guidance

To detect this vulnerability, check if your Snipe-IT instance is running a version before 8.7.0. Use the command: grep -r '8.7.0' /path/to/snipe-it/version or check the web interface footer. Inspect the Custom CSS field in the admin panel for suspicious @import or url() references pointing to external domains.

Impact Analysis

An attacker with superuser access could exploit this to steal CSRF tokens from other superusers. These tokens could then be used to forge requests, leading to full account takeover of other superuser accounts. The attack requires no user interaction beyond a victim superuser loading an authenticated page.

Mitigation Strategies

Immediately upgrade Snipe-IT to version 8.7.0 or later. If upgrading is not possible, remove all custom CSS entries in the admin panel and disable the Custom CSS feature. Monitor network traffic for unexpected external CSS requests from your Snipe-IT instance.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86738. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart