CVE-2026-86772

    Dashboard / Vulnerabilities / CVE-2026-86772

    CVE-2026-86772

    Published: 9 Sept 2026Last Modified: 12 Sept 2026

    Summary: Snipe-IT 8.6.3 Stored XSS via Department Names

    Details: Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for users without departments.view permission. Users with departments.edit permission can inject malicious scripts into department names that execute in the browsers of all department members when they load their My Assets page.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- cfd1ff8413e478a8daab700c15e96c96f93220e2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-86772 | CVE-DB