CVE-2026-37709

Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component
Configurations

Configuration 1 (hide)

cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*

History

12 May 2026, 20:29

Type Values Removed Values Added
First Time Snipeitapp
Snipeitapp snipe-it
CPE cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
References () https://github.com/grokability/snipe-it/commit/676a9958895a77de340565e7a0b17ae744664904 - () https://github.com/grokability/snipe-it/commit/676a9958895a77de340565e7a0b17ae744664904 - Patch
References () https://github.com/grokability/snipe-it/security/advisories/GHSA-xg82-2hrv-hf64 - () https://github.com/grokability/snipe-it/security/advisories/GHSA-xg82-2hrv-hf64 - Patch, Vendor Advisory

07 May 2026, 18:50

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-07 18:16

Updated : 2026-05-12 20:29


NVD link : CVE-2026-37709

Mitre link : CVE-2026-37709

CVE.ORG link : CVE-2026-37709


JSON object : View

Products Affected

snipeitapp

  • snipe-it
CWE
CWE-284

Improper Access Control