CVE-2026-37709

Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component
Configurations

Configuration 1 (hide)

cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-07 18:16

Updated : 2026-06-17 10:41


NVD link : CVE-2026-37709

Mitre link : CVE-2026-37709

CVE.ORG link : CVE-2026-37709


JSON object : View

Products Affected

snipeitapp

  • snipe-it
CWE
CWE-284

Improper Access Control