CVE-2026-86738
CVE-2026-86738
9.3
CriticalPublished:
Last updated:
Source:disclosure@vulncheck.com
Analyzed
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- High
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- None
- Confidentiality (Subsequent)
- High
- Integrity (Subsequent)
- High
- Availability (Subsequent)
- None
Description
Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using @import and url() references to exfiltrate CSRF tokens from other superusers via attribute-selector rules, enabling account takeover.
References
disclosure@vulncheck.com
https://github.com/grokability/snipe-it/commit/d26d71688359707f3b257fc04fe6c3e5a17405f9disclosure@vulncheck.com
https://github.com/grokability/snipe-it/security/advisories/GHSA-pvcw-mp8q-mj39disclosure@vulncheck.com
https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-css-injection-via-custom-css