CRITICAL 9.3 NVD
CVE-2026-86738
Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on great
Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using @import and url() references to exfiltrate CSRF tokens from other superusers via attribute-selector rules, enabling account takeover.
Affected Products
- snipeitapp/snipe-it
References
- https://github.com/grokability/snipe-it/commit/d26d71688359707f3b257fc04fe6c3e5a17405f9
- https://github.com/grokability/snipe-it/security/advisories/GHSA-pvcw-mp8q-mj39
- https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-css-injection-via-custom-css
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-08 via NVD. Affected: snipeitapp/snipe-it.
Risk Timeline
CVE Disclosed2026-09-08 · 2 days ago
Remediation Resources
Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-86733 | Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive dire | HIGH | 8.6 |
| CVE-2026-86734 | Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST | HIGH | 7.1 |
| CVE-2026-86735 | snipe-it versions before 8.7.0 contain a server-side request forgery vulnerabili | MEDIUM | 5.9 |
| CVE-2026-86736 | snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkou | MEDIUM | 5.3 |
| CVE-2026-86737 | snipe-it versions before 8.7.0 fail to enforce asset view authorization in the G | MEDIUM | 5.3 |
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.