What is CVE-2026-49870?
In Snipe-IT versions prior to 8.6.1, the "POST /two-factor" endpoint lacks rate limiting, allowing authenticated attackers to brute-force TOTP codes unlimitedly. This vulnerability can bypass two-factor authentication. Upgrading to version 8.6.1 is recommended.
Azərbaycanca: Snipe-IT-in 8.6.1-dən əvvəlki versiyalarında "POST /two-factor" endpoint-də rate limiting yoxdur, bu da autentifikasiya olunmuş şəxslərə TOTP kodlarını limitsiz sınaqdan keçirməyə imkan verir. Bu boşluqdan istifadə edən hücumçu brute-force ilə iki faktorlu autentifikasiyanı keçə bilər. Sistem 8.6.1 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Does exploiting CVE-2026-49870 require the attacker to be authenticated?
Yes, only authenticated attackers can exploit this vulnerability.
What version should be upgraded to in order to fix CVE-2026-49870?
The system should be upgraded to version 8.6.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.