CVE-2026-86772

Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for users without departments.view permission. Users with departments.edit permission can inject malicious scripts into department names that execute in the browsers of all department members when they load their My Assets page.
Configurations

Configuration 1 (hide)

cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*

History

16 Sep 2026, 20:28

Type Values Removed Values Added
First Time Snipeitapp snipe-it
Snipeitapp
References () https://github.com/grokability/snipe-it/security/advisories/GHSA-3j84-c68v-g76m - () https://github.com/grokability/snipe-it/security/advisories/GHSA-3j84-c68v-g76m - Exploit, Vendor Advisory
References () https://www.vulncheck.com/advisories/snipe-it-8.6.3-stored-xss-via-department-names - () https://www.vulncheck.com/advisories/snipe-it-8.6.3-stored-xss-via-department-names - Third Party Advisory
CPE cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*

Information

Published : 2026-09-09 14:17

Updated : 2026-09-16 20:28


NVD link : CVE-2026-86772

Mitre link : CVE-2026-86772

CVE.ORG link : CVE-2026-86772


JSON object : View

Products Affected

snipeitapp

  • snipe-it
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')