PT-2026-98144 · Snipe-It · Snipe-It

·

CVE-2026-63493

·

Published

2026-09-24

·

Updated

2026-09-29

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Snipe-IT versions prior to 8.7.0
Description An issue exists where the CheckForTwoFactor middleware is enforced in the web middleware group but not in the API middleware group. This allows a user who has authenticated with a password but has not yet completed the second-factor authentication (2FA) challenge to access the personal-access-token API flow. By accessing the /two-factor endpoint, an attacker can obtain a snipeit passport token cookie and subsequently request a persistent API token via the /api/v1/account/personal-access-tokens endpoint, provided the account has the self.api permission.
This persistent token grants full API access with the victim's permissions. If the victim is an administrator, the attacker can use the token to access the users/two factor reset endpoint to clear the account's enrolled 2FA. This enables the attacker to enroll their own second factor, effectively taking over the administrator's web account and locking out the legitimate user.
Recommendations Update Snipe-IT to version 8.7.0. As a temporary mitigation, restrict access to the /api/v1/account/personal-access-tokens endpoint or disable the self.api permission for users until the update is applied.

Exploit

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63493
GHSA-HXCX-9H4F-42XX

Affected Products

Snipe-It