[Git][security-tracker-team/security-tracker][master] Add new snipe-it issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 8 20:32:32 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
99bb3868 by Salvatore Bonaccorso at 2026-09-08T21:32:11+02:00
Add new snipe-it issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -15,17 +15,17 @@ CVE-2026-86840 (The `vtoken-minting` and `slpx` pallets in Bifrost contain an im
CVE-2026-86804 (A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.1 ...)
NOT-FOR-US: seakee CPA-Manager-Plus
CVE-2026-86738 (Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability i ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86737 (snipe-it versions before 8.7.0 fail to enforce asset view authorizatio ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86736 (snipe-it before 8.7.0 contains an incorrect calculation vulnerability ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86735 (snipe-it versions before 8.7.0 contain a server-side request forgery v ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86734 (Snipe-IT before 8.7.1 fails to validate the length of the note field i ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86733 (Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup ar ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86732 (Craft CMS versions before 5.10.12 contain a remote code execution vuln ...)
NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-86731 (Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-targ ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/99bb38681e4d0347321919cd2eb1c7583da869d1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/99bb38681e4d0347321919cd2eb1c7583da869d1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260908/7f8fb589/attachment.htm>
More information about the debian-security-tracker-commits
mailing list