CRITICAL 9.3 NVD

CVE-2026-86738

Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on great

Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using @import and url() references to exfiltrate CSRF tokens from other superusers via attribute-selector rules, enabling account takeover.

Affected Products

References

Published: 2026-09-08 · Source: NVD · Feed updated: 2026-09-11
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-08 via NVD. Affected: snipeitapp/snipe-it.

Risk Timeline

CVE Disclosed2026-09-08 · 2 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-86733Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive direHIGH8.6
CVE-2026-86734Snipe-IT before 8.7.1 fails to validate the length of the note field in the POSTHIGH7.1
CVE-2026-86735snipe-it versions before 8.7.0 contain a server-side request forgery vulnerabiliMEDIUM5.9
CVE-2026-86736snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkouMEDIUM5.3
CVE-2026-86737snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GMEDIUM5.3
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.