CVE-2026-63493 — Snipe-IT is an IT asset/license management system.
Description
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-token API flow before completing the account's second-factor challenge because CheckForTwoFactor is enforced in the web middleware group but not the API middleware group. The advisory states that the resulting persistent API token can read and modify resources with the victim's permissions and, for an administrator, can reach the users/two_factor_reset endpoint. Resetting the administrator's enrolled second factor allows the password-holding attacker to enroll an attacker-controlled factor, take over the administrator's web account, and lock out the legitimate user. The token does not create a web session, but it provides broad API access while the same browser session remains blocked at the two-factor page. This vulnerability is fixed in 8.7.0.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
None
Attack Requirements
PR
Low
Privileges Required
UI
None
User Interaction
VC
High
Confidentiality (Vulnerable System)
VI
High
Integrity (Vulnerable System)
VA
None
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
Affected
- Vendor
- snipeitapp
- Product
- snipe-it
Versions
- < 8.7.0
Stated as the source expressed them.
References
- patchPatchhttps://github.com/grokability/snipe-it/commit/87c362962a670f427be071850b218e43eff5d08e
- patchPatchhttps://github.com/grokability/snipe-it/commit/c4ea7db51ca80bf11b1d04fbe46e4a64f54dc780
- patchPatchhttps://github.com/grokability/snipe-it/pull/19294
- advisoryRelease Noteshttps://github.com/grokability/snipe-it/releases/tag/v8.7.0
- patchExploithttps://github.com/grokability/snipe-it/security/advisories/GHSA-hxcx-9h4f-42xx
Related threats
same CWE or vendorCVE-2026-104075 — TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerability in the web management …
CVE-2026-104075 · 3h ago
CVE-2026-107361 — The Arkime live capture service (arkime-live) in Malcolm runs with network_mode: host, exposing port 8005 on all network interfaces (viewHost=0.0.0…
CVE-2026-107361 · 5h ago
CVE-2026-94585 — An authentication bypass vulnerability exists in the web management interface of Brocade Fabric OS versions before 9.2.2d running on the MXG610 pla…
CVE-2026-94585 · 18h ago
CVE-2026-107194 — Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "…
CVE-2026-107194 · 1d ago
CVE-2026-19572 — A security vulnerability has been identified in FlexNet Publisher lmadmin.
CVE-2026-19572 · 2d ago
CVE-2026-39793 — Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions.
CVE-2026-39793 · 3d ago