CVE-2026-86745
Analyzed Analyzed - Analysis Complete

CSV Formula Injection in Snipe-IT Asset Management

Vulnerability report for CVE-2026-86745, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

Snipe-IT is an IT asset management application. In Snipe-IT master-branch builds after 8.6.3 (the code was never included in a tagged release), SettingsController::downloadLocationScopingReport streams the FMCS location-scoping mismatch report (GET /admin/settings/location-scoping-report.csv) through a bare fputcsv() call without applying League\Csv\EscapeFormula, unlike the other CSV exports which honor config('app.escape_formulas'). An authenticated user with ordinary create/edit rights can place a spreadsheet formula in free-text fields that appear in the report (item name, asset tag, serial, item or location company name, location name) and arrange for the record to be FMCS-mismatched so it is included in the export. When a superuser downloads the report and opens it in Excel, LibreOffice Calc, or Google Sheets with formula evaluation enabled and external-content warnings dismissed or disabled, cells beginning with =, +, -, @, tab, or CR are executed in the victim's spreadsheet context, enabling data exfiltration (e.g., HYPERLINK/WEBSERVICE) or, on Windows Excel, legacy DDE command execution. This issue is fixed in version 8.7.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
snipeitapp snipe-it 8.6.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1236 The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86745 is a CSV formula injection vulnerability in Snipe-IT, an IT asset management system. It affects versions after 8.6.3 in the master branch but was fixed in 8.7.0. The issue occurs in the FMCS location-scoping export feature where CSV data is streamed without escaping spreadsheet formulas. Authenticated users with basic edit rights can insert formulas into fields like item names or asset tags, which are then executed when a superuser opens the CSV in Excel or similar software with formula evaluation enabled.

Detection Guidance

Check if your Snipe-IT instance is running a version before 8.7.0 by inspecting the version file or admin panel. Look for suspicious formulas in free-text fields like item names, asset tags, or location names that could be used in CSV exports. Monitor network traffic for unexpected outbound connections from workstations where superusers open CSV files.

Impact Analysis

This vulnerability allows an attacker to execute spreadsheet formulas when a superuser opens the malicious CSV file. This could lead to data exfiltration via functions like HYPERLINK or WEBSERVICE, or even legacy DDE command execution on Windows Excel. The impact is limited to the superuser's workstation and requires the superuser to open the file with formula evaluation enabled.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA due to the risk of data exfiltration. If a superuser opens the malicious CSV in a spreadsheet application with formula evaluation enabled, formulas like HYPERLINK or WEBSERVICE could be executed to send sensitive data to external servers. This unauthorized data transfer could lead to breaches of confidentiality requirements under both GDPR (Article 5) and HIPAA (45 CFR Β§ 164.502).

Mitigation Strategies

Upgrade Snipe-IT to version 8.7.0 or later immediately. If upgrading is not possible, disable the location-scoping export feature by removing the vulnerable endpoint or restricting access to it. Ensure config('app.escape_formulas') is enabled and verify other CSV exports use League\Csv\EscapeFormula.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86745. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart