Medium · 4.9 PHP packages GHSA-hxcx-9h4f-42xx CVE-2026-63493 PKSA-2634-9r51-kjsx GHSA-p9h3-gvpq-5539
Snipe-IT 8.7.0 fixes 2FA bypass and two stored XSS vulnerabilities
Snipe-IT versions before 8.7.0 contain three vulnerabilities: a two-factor authentication bypass via the API token flow (CVE-2026-63493) that can lead to administrator account takeover, and two stored cross-site scripting issues (CVE-2026-62368, CVE-2026-63498) that can expose session data and perform actions as a victim user. All three are fixed in version 8.7.0.
- GitHub Advisory Database database 2w ago · view ↗
- Packagist Security Advisories registry 2w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- GitHub Advisory Database database 2w ago · view ↗
- Packagist Security Advisories registry 2w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- GitHub Advisory Database database 2w ago · view ↗
- Packagist Security Advisories registry 2w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
AI summary
Snipe-IT, an open-source IT asset and license management system, has released version 8.7.0 to address three separately tracked vulnerabilities disclosed on the same day. The most serious allows a password-authenticated attacker to bypass two-factor authentication through the API and, for administrator accounts, take over the victim's web session. The other two are stored cross-site scripting (XSS) issues that can expose session data and let an attacker act with a victim's privileges. All three affect versions prior to 8.7.0 and are resolved in that release.
Three vulnerabilities disclosed and fixed together
On the same day, three advisories were published for Snipe-IT, all affecting versions prior to 8.7.0 and all resolved in 8.7.0: 1. CVE-2026-63493 (CWE-288, Authentication Bypass Using an Alternate Path or Channel): A password-authenticated user with self.api permission can reach the personal-access-token API flow before completing their second-factor challenge, because the CheckForTwoFactor check is enforced in the web middleware group but not in the API middleware group. 2. CVE-2026-62368 (CWE-79, stored Cross-Site Scripting): A user with the customfields.create permission can store markup in a custom field name, which is rendered unescaped as a bootstrap-table header title in app/Presenters/AssetPresenter.php, executing when another user views an associated asset list. 3. CVE-2026-63498 (CWE-79, stored Cross-Site Scripting): An authenticated user with file-management access can upload XML/XSLT attachments and request them via the inline=true parameter on the uploaded-files API endpoint. The API controller does not apply the safe-inline allowlist used by the equivalent web controller, allowing an attacker-controlled xml-stylesheet reference to execute JavaScript in the Snipe-IT origin when a victim opens the attachment URL.
Root causes
CVE-2026-63493 stems from an inconsistency between middleware groups: the two-factor check (CheckForTwoFactor) is applied to the web routes but not to the API routes, so a personal-access-token can be created through the API before the second factor is completed. This token does not create a web session but does grant broad API access tied to the victim's permissions, and for an administrator account it can reach the users/two_factor_reset endpoint, allowing the attacker to reset and re-enroll the admin's second factor. CVE-2026-62368 results from unescaped output: CustomField.name values are stored and later rendered directly as bootstrap-table header titles without sanitization, allowing stored markup to execute in the browser of any user who views an asset list using that field. CVE-2026-63498 results from an inconsistency between controllers: the API's UploadedFilesController show() method does not apply the same safe-inline allowlist that the web controller uses when serving files with inline=true, allowing XML/XSLT attachments to trigger browser-side script execution via an xml-stylesheet reference.
Why these issues matter
CVE-2026-63493 can lead to full administrator account takeover: an attacker who has obtained an administrator's password (but not yet their second factor) can use the API to reset the administrator's enrolled 2FA device, enroll one they control, and lock the legitimate administrator out while the browser session remains stuck at the two-factor prompt. The two XSS issues (CVE-2026-62368 and CVE-2026-63498) allow attacker-controlled script to execute in another user's authenticated session, exposing same-origin data and allowing actions to be performed with that user's privileges; for CVE-2026-62368, the advisory specifically notes this can result in privilege escalation if a superuser views the affected asset list.
Who is affected
Organizations running Snipe-IT prior to version 8.7.0 are affected. CVE-2026-63493 requires an attacker to already hold valid password credentials for an account with self.api permission. CVE-2026-62368 requires a user with customfields.create permission to create the malicious field, after which any user (including a superuser) viewing an affected asset list is at risk. CVE-2026-63498 requires an authenticated user with file-management access to upload the malicious attachment, after which any user authorized to view that object and who opens the attachment URL is at risk.
Affected and fixed versions
All three vulnerabilities affect snipe/snipe-it versions prior to 8.7.0. All three are fixed in version 8.7.0.
Fix available
Snipe-IT 8.7.0 resolves all three vulnerabilities. The fact package does not describe interim mitigations or workarounds for installations that cannot immediately update.
Recommended action
Update Snipe-IT to version 8.7.0 as soon as possible. Given the combination of a 2FA-bypass-to-admin-takeover path and two stored XSS vulnerabilities reachable by authenticated users, administrators should prioritize this update, and after updating, review custom field definitions and uploaded attachments for any unexpected or suspicious content that may have been introduced before the fix was applied.
PatchBriefing score
4.9 / 10 · Medium
Official CVSS: 8.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Why this score
The three advisories carry patchwire scores of 4.9, 4.5, and 4.8 (on the platform's scale), driven primarily by their CVSS base scores of 8.6, 8.1, and 8.7 respectively. None of the three has a known exploit in the wild, a public exploit, or elevated EPSS score, and none is unauthenticated-remote, which keeps the overall patchwire scores in the moderate-high range rather than critical. CVE-2026-63493 additionally receives a small contribution because no user interaction is required to bypass 2FA via the API. All three have a fix available, which prevents the score from increasing for that factor.
Affected versions
- snipe/snipe-it < 8.7.0
- vulnerable
- snipe/snipe-it <8.7.0
- vulnerable
- ≥ 8.7.0
- patched
- snipe/snipe-it < 8.7.0
- vulnerable
- snipe/snipe-it <8.7.0
- vulnerable
- ≥ 8.7.0
- patched
- snipe/snipe-it < 8.7.0
- vulnerable
- snipe/snipe-it <8.7.0
- vulnerable
- ≥ 8.7.0
- patched
Reported fixes
Snipe-IT 8.7.0 resolves all three vulnerabilities. The fact package does not describe interim mitigations or workarounds for installations that cannot immediately update.
How this was built
9 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
Packagist Security Advisories registry
-
NVD (NIST) database
-
GitHub Advisory Database database
-
Packagist Security Advisories registry
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email