CVE-2026-86772
Undergoing Analysis Undergoing Analysis - In Progress

Stored XSS in Snipe-IT Asset Management System

Vulnerability report for CVE-2026-86772, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: VulnCheck

Description

Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for users without departments.view permission. Users with departments.edit permission can inject malicious scripts into department names that execute in the browsers of all department members when they load their My Assets page.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
grokability snipe-it to 8.7.0 (exc)
grokability snipe-it to 8.6.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86772 is a stored cross-site scripting (XSS) vulnerability in Snipe-IT versions before 8.7.0. It occurs in the DepartmentPresenter::formattedNameLink() function where department names are rendered unescaped for users without departments.view permission. Attackers with departments.edit permission can inject malicious scripts into department names. When other users load their My Assets page, the scripts execute in their browsers.

Detection Guidance

Check Snipe-IT version with: grep -r "version" /path/to/snipe-it/config/app.php. If version is below 8.7.0, the system is vulnerable. Review department names for suspicious scripts in the database with: SELECT name FROM departments WHERE name LIKE '%<script>%' OR name LIKE '%javascript:%'.

Inspect browser requests to the My Assets page for unexpected scripts in department name responses. Monitor user reports of unusual behavior on the My Assets page.

Impact Analysis

This vulnerability allows attackers to inject malicious scripts into department names. When users without departments.view permission access their My Assets page, the scripts execute in their browsers. This could lead to account takeover, privilege escalation, or unauthorized actions on behalf of the user.

Compliance Impact

This stored XSS vulnerability could lead to unauthorized access to sensitive data, which may violate GDPR's data protection requirements or HIPAA's safeguards for protected health information. Attackers could exploit it to steal session tokens, access restricted data, or perform actions on behalf of users, potentially resulting in non-compliance with these regulations.

Mitigation Strategies

Upgrade Snipe-IT to version 8.7.0 or later immediately. If upgrading is not possible, revoke departments.edit and departments.create permissions from non-superusers until patched.

Review department names for any injected scripts and remove them. Monitor for unusual activity in user accounts after mitigation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86772. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart