PT-2026-39301 · Grokability+2 · Snipe-It+1

Ce2Sec

·

Published

2026-05-08

·

Updated

2026-05-26

·

CVE-2026-44833

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Snipe-IT versions prior to 8.4.1
Description An open redirect issue in Snipe-IT allows attackers to redirect users to malicious websites. This occurs because the application uses an unvalidated HTTP Referer header stored in a session variable. When a user clicks "Save", the application processes the form and, if the redirect option is set to 'back', it calls the Helper::getRedirectOption() function to retrieve the back url from the session and executes redirect()->to($backUrl). This can be leveraged for phishing, session hijacking, malware distribution, and social engineering.
Recommendations Update to version 8.4.1.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44833
GHSA-MGHP-5CQ4-V6MG

Affected Products

Snipe-It
Snipe/Snipe-It