CVE-2026-86757
Undergoing Analysis Undergoing Analysis - In Progress

Snipe-IT Encrypted Custom Field Exposure via Form Template

Vulnerability report for CVE-2026-86757, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: VulnCheck

Description

Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field values in asset form templates for listbox, textarea, markdown-textarea, and date/datetime picker elements. Authenticated users with assets.edit, assets.checkin, assets.checkout, or assets.audit permissions can read plaintext encrypted custom field values by opening asset forms, bypassing the assets.view.encrypted_custom_fields permission check.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
snipe-it snipe-it to 8.7.0 (exc)
grokability snipe-it to 8.7.0 (exc)
grokability snipe-it 8.6.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Snipe-IT before version 8.7.0 has a flaw where encrypted custom field values in asset forms are displayed as plaintext. Authenticated users with certain permissions can bypass the intended access control and view sensitive encrypted data without the required decryption permission.

Detection Guidance

Check Snipe-IT version with: grep -r "version" /path/to/snipe-it/config/app.php. If version is below 8.7.0, the system is vulnerable. Review user permissions for assets.edit, assets.checkin, assets.checkout, or assets.audit. Inspect asset form templates for custom_fields_form.blade.php to confirm missing permission checks.

Impact Analysis

This vulnerability allows unauthorized users to access sensitive encrypted data such as BitLocker recovery keys, WiFi passwords, admin passwords, and license keys. Attackers with specific permissions could exploit this to steal confidential information.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive encrypted data such as passwords, license keys, or recovery keys. For GDPR, this may violate principles of data protection and confidentiality, potentially resulting in unauthorized data exposure. For HIPAA, it could compromise protected health information if such data is stored in custom fields.

Mitigation Strategies

Upgrade Snipe-IT to version 8.7.0 or later immediately. Temporarily restrict permissions assets.edit, assets.checkin, assets.checkout, and assets.audit to users who also have assets.view.encrypted_custom_fields until patched. Audit all encrypted custom fields for exposed sensitive data like BitLocker keys or passwords.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86757. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart