Snipe-It · Snipe-It · CVE-2026-63493
**Name of the Vulnerable Software and Affected Versions**
Snipe-IT versions prior to 8.7.0
**Description**
An issue exists where the `CheckForTwoFactor` middleware is enforced in the web middleware group but not in the API middleware group. This allows a user who has authenticated with a password but has not yet completed the second-factor authentication (2FA) challenge to access the personal-access-token API flow. By accessing the `/two-factor` endpoint, an attacker can obtain a `snipeit passport token` cookie and subsequently request a persistent API token via the `/api/v1/account/personal-access-tokens` endpoint, provided the account has the `self.api` permission.
This persistent token grants full API access with the victim's permissions. If the victim is an administrator, the attacker can use the token to access the `users/two factor reset` endpoint to clear the account's enrolled 2FA. This enables the attacker to enroll their own second factor, effectively taking over the administrator's web account and locking out the legitimate user.
**Recommendations**
Update Snipe-IT to version 8.7.0.
As a temporary mitigation, restrict access to the `/api/v1/account/personal-access-tokens` endpoint or disable the `self.api` permission for users until the update is applied.