PT-2026-38544 · Grokability · Snipe-It

0Xaspros

·

Published

2026-05-07

·

Updated

2026-05-12

·

CVE-2026-37709

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions grokability snipe-it versions prior to 8.4.1
Description Insecure permissions allow a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component. Users with permissions to view assets or consumables can send a POST request to the "/api/v1/{object type}/{id}/files" endpoint. The API incorrectly authorizes these requests using view permissions instead of write permissions, allowing the persistence of files and audit log entries.
Recommendations Update to version 8.4.1.

Fix

RCE

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-37709
GHSA-XG82-2HRV-HF64

Affected Products

Snipe-It