CVE-2026-86771
Undergoing Analysis Undergoing Analysis - In Progress

HTML Image Tag Injection in Snipe-IT PDF Generator

Vulnerability report for CVE-2026-86771, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: VulnCheck

Description

Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() function. Attackers can craft a malicious employee_num value containing an img tag with an arbitrary HTTP(S) URL to trigger server-side requests to internal services, cloud metadata endpoints, or external targets when a victim signs an asset acceptance.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
snipe-it snipe-it to 8.7.0 (exc)
grokability snipe-it From 8.6.3 (inc) to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in Snipe-IT versions before 8.7.0. Attackers with users.edit permission can inject malicious img tags into the employee_num field of the acceptance PDF generator. When a victim signs an asset acceptance, the server processes the malicious tag, triggering server-side requests to internal services, cloud metadata endpoints, or external targets via TCPDF's writeHTML() function.

Detection Guidance

To detect this vulnerability, inspect Snipe-IT instances running versions before 8.7.0 for unauthorized outbound HTTP(S) requests originating from the server during PDF generation. Check logs for TCPDF writeHTML() calls with img tags containing suspicious URLs. Review network traffic for connections to internal services or cloud metadata endpoints triggered by asset acceptance PDFs.

Impact Analysis

An attacker could exfiltrate sensitive data like cloud metadata service credentials (e.g., AWS IMDSv1) or access internal services. The attack requires the victim to sign an acceptance for an assigned asset, which triggers PDF generation and processes the malicious employee_num value.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating confidentiality requirements in GDPR and HIPAA. Exposure of sensitive metadata or internal service data may result in compliance breaches, fines, or legal consequences depending on the data involved.

Mitigation Strategies

Immediately upgrade Snipe-IT to version 8.7.0 or later to patch the vulnerability. If upgrading is not possible, disable TCPDF's remote image fetching in the configuration. Additionally, enforce strict input validation for the employee_num field to prevent HTML injection. Restrict server outbound connections to trusted networks only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86771. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart