CVE-2026-62368
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-table header title. When another user opens an asset-list page associated with the fieldset, the stored markup executes on page load in that user's Snipe-IT session. This can expose same-origin data and perform authenticated actions with the victim's privileges, including privilege escalation when a superuser views the affected list. This issue is fixed in version 8.7.0.
Not on KEV
Not in CISA's Known Exploited Vulnerabilities catalogue as of the last daily pull. Absence is not proof of safety.
—
FIRST has not scored this id yet.
8.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
—
No exposure census on this CVE's dispatches.
- nvd.nist.gov ↗
- first.org · EPSS ↗
- github.com/grokability/snipe-it/commit/58754e4e3b86b58a0c4523012ef04a2ae990d2c8 ↗
- github.com/grokability/snipe-it/releases/tag/v8.7.0 ↗
- github.com/grokability/snipe-it/security/advisories/GHSA-p9h3-gvpq-5539 ↗
- github.com/grokability/snipe-it/security/advisories/GHSA-p9h3-gvpq-5539 ↗
Watch this one?
Early access opens alerts first — one email when a CVE you follow lands on KEV or an adversary you follow lands on the wire. Nothing else, ever.