Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Colinthebomb1

#32974of 57,416
8.6Total CVSS
Vulnerabilities · 1
PT-2026-98144
8.6
2026-09-24
Snipe-It · Snipe-It · CVE-2026-63493
**Name of the Vulnerable Software and Affected Versions** Snipe-IT versions prior to 8.7.0 **Description** An issue exists where the `CheckForTwoFactor` middleware is enforced in the web middleware group but not in the API middleware group. This allows a user who has authenticated with a password but has not yet completed the second-factor authentication (2FA) challenge to access the personal-access-token API flow. By accessing the `/two-factor` endpoint, an attacker can obtain a `snipeit passport token` cookie and subsequently request a persistent API token via the `/api/v1/account/personal-access-tokens` endpoint, provided the account has the `self.api` permission. This persistent token grants full API access with the victim's permissions. If the victim is an administrator, the attacker can use the token to access the `users/two factor reset` endpoint to clear the account's enrolled 2FA. This enables the attacker to enroll their own second factor, effectively taking over the administrator's web account and locking out the legitimate user. **Recommendations** Update Snipe-IT to version 8.7.0. As a temporary mitigation, restrict access to the `/api/v1/account/personal-access-tokens` endpoint or disable the `self.api` permission for users until the update is applied.