OCTOBER 2, 2026
Live Feed
Back to database
Case File

CVE-2026-62368

HIGH · CVSS 8.1 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-02

CyberRota Analysis

AI-Generated

Snipe-IT versions prior to 8.7.0 are vulnerable to a stored cross-site scripting (XSS) attack, where a user with the customfields.create permission can inject malicious markup into the CustomField.name. This vulnerability allows an attacker to execute arbitrary scripts in the context of another user's session, potentially exposing sensitive data and enabling unauthorized actions, including privilege escalation. Organizations using affected versions should prioritize upgrading to version 8.7.0 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-62368
Severity
HIGH
CVSS
8.1
EPSS
0.35%

Original NVD Description

Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-table header title. When another user opens an asset-list page associated with the fieldset, the stored markup executes on page load in that user's Snipe-IT session. This can expose same-origin data and perform authenticated actions with the victim's privileges, including privilege escalation when a superuser views the affected list. This issue is fixed in version 8.7.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)