[Git][security-tracker-team/security-tracker][master] Add new snipe-it issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 9 21:27:27 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ac60afc7 by Salvatore Bonaccorso at 2026-09-09T22:26:32+02:00
Add new snipe-it issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -87,77 +87,77 @@ CVE-2026-86776 (KeePass versions 2.35 through 2.61.1 fail to validate KDBX heade
CVE-2026-86775 (knowns (npm package) versions <= 0.29.1 contain a path traversal vulne ...)
TODO: check
CVE-2026-86774 (Snipe-IT versions before 8.7.0 contain a broken access control vulnera ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86773 (Snipe-IT through version 8.6.3 fails to perform object-level authoriza ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86772 (Snipe-IT versions before 8.7.0 contain a stored cross-site scripting v ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86771 (Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num fi ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86770 (Snipe-IT before 8.7.0 fails to validate username case sensitivity duri ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86769 (Snipe-IT versions before 8.7.0 contain an improper ownership managemen ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86768 (Snipe-IT before 8.7.0 fails to validate soft-deleted state in API chec ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86767 (Snipe-IT versions before 8.7.0 fail to apply company scope filtering t ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86766 (Snipe-IT versions up to and including 8.6.3 contain a race condition ( ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86765 (Snipe-IT versions before 8.7.0 fail to enforce checkout authorization ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86764 (Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the component ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86763 (Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypa ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86762 (Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middlewa ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86761 (snipe-it versions before 8.7.0 contain an authorization bypass vulnera ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86760 (Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an inco ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86759 (Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/hi ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86758 (Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authoriza ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86757 (Snipe-IT before 8.7.0 fails to properly gate access to encrypted custo ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86756 (Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability i ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86755 (Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-r ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86754 (Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86753 (snipe-it versions before 8.7.0 fail to validate the requestable flag f ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86752 (snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scopi ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86751 (Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86750 (Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company as ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86749 (Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return va ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86748 (Snipe-IT versions before 8.7.0 wipe the database before validating the ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86747 (Snipe-IT is an open source IT asset management system. In versions up ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86746 (Snipe-IT before 8.7.0 contains an authorization bypass vulnerability i ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86745 (Snipe-IT is an IT asset management application. In Snipe-IT master-bra ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86744 (Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to t ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86743 (Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86742 (Snipe-IT through 8.6.3 does not neutralize formula elements in the "un ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86741 (Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86740 (Snipe-IT before 8.7.0 fails to check the return value of Storage::dele ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86739 (Snipe-IT 8.6.3 and earlier do not check the return value of Storage::p ...)
- TODO: check
+ - snipe-it <itp> (bug #1005172)
CVE-2026-86547 (mrubyc through 4.0.0 contains a null pointer dereference vulnerability ...)
TODO: check
CVE-2026-86204 (PocketMine-MP versions before 5.39.2 fail to limit JSON payload size i ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac60afc7bad86d7de4547f784b0a9b78459d31c2
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac60afc7bad86d7de4547f784b0a9b78459d31c2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260909/88559b9b/attachment.htm>
More information about the debian-security-tracker-commits
mailing list