[Git][security-tracker-team/security-tracker][master] Add new snipe-it issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 9 21:27:27 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ac60afc7 by Salvatore Bonaccorso at 2026-09-09T22:26:32+02:00
Add new snipe-it issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -87,77 +87,77 @@ CVE-2026-86776 (KeePass versions 2.35 through 2.61.1 fail to validate KDBX heade
 CVE-2026-86775 (knowns (npm package) versions <= 0.29.1 contain a path traversal vulne ...)
 	TODO: check
 CVE-2026-86774 (Snipe-IT versions before 8.7.0 contain a broken access control vulnera ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86773 (Snipe-IT through version 8.6.3 fails to perform object-level authoriza ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86772 (Snipe-IT versions before 8.7.0 contain a stored cross-site scripting v ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86771 (Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num fi ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86770 (Snipe-IT before 8.7.0 fails to validate username case sensitivity duri ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86769 (Snipe-IT versions before 8.7.0 contain an improper ownership managemen ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86768 (Snipe-IT before 8.7.0 fails to validate soft-deleted state in API chec ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86767 (Snipe-IT versions before 8.7.0 fail to apply company scope filtering t ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86766 (Snipe-IT versions up to and including 8.6.3 contain a race condition ( ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86765 (Snipe-IT versions before 8.7.0 fail to enforce checkout authorization  ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86764 (Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the component ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86763 (Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypa ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86762 (Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middlewa ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86761 (snipe-it versions before 8.7.0 contain an authorization bypass vulnera ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86760 (Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an inco ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86759 (Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/hi ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86758 (Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authoriza ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86757 (Snipe-IT before 8.7.0 fails to properly gate access to encrypted custo ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86756 (Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability i ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86755 (Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-r ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86754 (Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth  ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86753 (snipe-it versions before 8.7.0 fail to validate the requestable flag f ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86752 (snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scopi ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86751 (Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86750 (Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company as ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86749 (Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return va ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86748 (Snipe-IT versions before 8.7.0 wipe the database before validating the ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86747 (Snipe-IT is an open source IT asset management system. In versions up  ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86746 (Snipe-IT before 8.7.0 contains an authorization bypass vulnerability i ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86745 (Snipe-IT is an IT asset management application. In Snipe-IT master-bra ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86744 (Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to t ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86743 (Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86742 (Snipe-IT through 8.6.3 does not neutralize formula elements in the "un ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86741 (Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86740 (Snipe-IT before 8.7.0 fails to check the return value of Storage::dele ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86739 (Snipe-IT 8.6.3 and earlier do not check the return value of Storage::p ...)
-	TODO: check
+	- snipe-it <itp> (bug #1005172)
 CVE-2026-86547 (mrubyc through 4.0.0 contains a null pointer dereference vulnerability ...)
 	TODO: check
 CVE-2026-86204 (PocketMine-MP versions before 5.39.2 fail to limit JSON payload size i ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac60afc7bad86d7de4547f784b0a9b78459d31c2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac60afc7bad86d7de4547f784b0a9b78459d31c2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260909/88559b9b/attachment.htm>


More information about the debian-security-tracker-commits mailing list