CVE-2026-86742
Analyzed Analyzed - Analysis Complete

CSV Formula Injection in Snipe-IT

Vulnerability report for CVE-2026-86742, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export. ReportsController::postAssetAcceptanceReport builds the CSV by hand (stripping commas and joining rows manually) and, unlike the six sibling exports in the same controller, never applies League\Csv\EscapeFormula or honors the config('app.escape_formulas') setting. An authenticated low-privilege user with ordinary create/edit rights on any record whose free-text fields appear in the report (asset name/tag, company name, category, model, or assignee display name) can set such a field to a value beginning with =, +, -, @, tab, or CR. When a user with reports.view privileges requests the export (POST /reports/unaccepted_assets) for a pending checkout acceptance referencing the poisoned record and opens the resulting CSV in Excel, LibreOffice Calc, or Google Sheets, the injected content is evaluated as a formula in the downloader's spreadsheet context, enabling data exfiltration (e.g., HYPERLINK/WEBSERVICE) or, on legacy Windows Excel configurations, DDE command execution. Fixed in 8.7.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
snipeitapp snipe-it to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1236 The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86742 is a CSV formula injection vulnerability in Snipe-IT versions before 8.7.0. It allows authenticated low-privilege users to inject malicious formulas into free-text fields like asset names or company names. When a user with report access exports and opens the CSV in spreadsheet software, the formulas execute, enabling data exfiltration or command execution.

Detection Guidance

To detect this vulnerability, check if your Snipe-IT instance is running a version before 8.7.0. Inspect the ReportsController.php file for the postAssetAcceptanceReport function to see if it manually constructs CSV without using League\Csv\EscapeFormula. Look for free-text fields like asset names or company names that could contain formula prefixes (=, +, -, @, tab, CR).

Commands to check version: grep -r "version" /path/to/snipe-it/config/app.php or check the footer in the web interface. Review CSV export functionality for the unaccepted assets report.

Impact Analysis

An attacker could exfiltrate sensitive data via HYPERLINK or WEBSERVICE functions or execute DDE commands on older Windows Excel systems. This requires the victim to open the malicious CSV file, but could lead to unauthorized data access or system compromise depending on the spreadsheet application.

Compliance Impact

This vulnerability could lead to unauthorized data exfiltration or access, violating GDPR's data protection principles or HIPAA's confidentiality requirements. Organizations using affected Snipe-IT versions may face compliance risks if sensitive data is exposed through this flaw.

Mitigation Strategies

Immediately upgrade Snipe-IT to version 8.7.0 or later to apply the fix for CSV formula injection. If upgrading is not possible, disable the unaccepted assets report export feature or restrict access to users with reports.view privileges.

Ensure the app.escape_formulas configuration setting is enabled in your Snipe-IT environment to enforce formula escaping in all CSV exports.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86742. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart