SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-86742

MEDIUM · CVSS 6.5 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Snipe-IT versions up to 8.6.3 are vulnerable due to improper handling of formula elements in the CSV export of unaccepted assets, allowing low-privilege authenticated users to inject malicious formulas into free-text fields. This vulnerability can lead to data exfiltration or command execution when the exported CSV is opened in spreadsheet applications like Excel or Google Sheets. Organizations using affected versions should prioritize patching to version 8.7.0 to mitigate potential security risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86742
Severity
MEDIUM
CVSS
6.5
EPSS
0.27%
Windows Office

Original NVD Description

Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export. ReportsController::postAssetAcceptanceReport builds the CSV by hand (stripping commas and joining rows manually) and, unlike the six sibling exports in the same controller, never applies League\Csv\EscapeFormula or honors the config('app.escape_formulas') setting. An authenticated low-privilege user with ordinary create/edit rights on any record whose free-text fields appear in the report (asset name/tag, company name, category, model, or assignee display name) can set such a field to a value beginning with =, +, -, @, tab, or CR. When a user with reports.view privileges requests the export (POST /reports/unaccepted_assets) for a pending checkout acceptance referencing the poisoned record and opens the resulting CSV in Excel, LibreOffice Calc, or Google Sheets, the injected content is evaluated as a formula in the downloader's spreadsheet context, enabling data exfiltration (e.g., HYPERLINK/WEBSERVICE) or, on legacy Windows Excel configurations, DDE command execution. Fixed in 8.7.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)