SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-86771

HIGH · CVSS 7.6 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Snipe-IT versions prior to 8.7.0 are vulnerable due to insufficient HTML escaping in the employee_num field of the acceptance PDF generator, allowing users with edit permissions to inject malicious img tags. This vulnerability can lead to server-side requests to internal services or external targets, posing a significant risk of data exposure or unauthorized access. Organizations using affected versions should prioritize patching to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86771
Severity
HIGH
CVSS
7.6
EPSS
0.19%

Original NVD Description

Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() function. Attackers can craft a malicious employee_num value containing an img tag with an arbitrary HTTP(S) URL to trigger server-side requests to internal services, cloud metadata endpoints, or external targets when a victim signs an asset acceptance.