Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for users without departments.view permission. Users with departments.edit permission can inject malicious scripts into department names that execute in the browsers of all department members when they load their My Assets page.
References
| Link | Resource |
|---|---|
| https://github.com/grokability/snipe-it/security/advisories/GHSA-3j84-c68v-g76m | Exploit Vendor Advisory |
| https://www.vulncheck.com/advisories/snipe-it-8.6.3-stored-xss-via-department-names | Third Party Advisory |
Configurations
History
16 Sep 2026, 20:28
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Snipeitapp snipe-it
Snipeitapp |
|
| References | () https://github.com/grokability/snipe-it/security/advisories/GHSA-3j84-c68v-g76m - Exploit, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/snipe-it-8.6.3-stored-xss-via-department-names - Third Party Advisory | |
| CPE | cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:* |
Information
Published : 2026-09-09 14:17
Updated : 2026-09-16 20:28
NVD link : CVE-2026-86772
Mitre link : CVE-2026-86772
CVE.ORG link : CVE-2026-86772
JSON object : View
Products Affected
snipeitapp
- snipe-it
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
