Snipe-It · Snipe-It · CVE-2026-62368
**Name of the Vulnerable Software and Affected Versions**
Snipe-IT versions prior to 8.7.0
**Description**
A user with the `customfields.create` permission can store malicious markup in the `CustomField.name` variable. The `app/Presenters/AssetPresenter.php` file assigns this value as an unescaped bootstrap-table header title. When another user, including a superuser, opens an asset-list page such as the `/hardware` endpoint, the stored markup executes automatically on page load. This allows an attacker to expose same-origin data and perform authenticated actions with the victim's privileges, potentially leading to privilege escalation.
**Recommendations**
Update Snipe-IT to version 8.7.0.