Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-86746

Snipe-IT before 8.7.0 contains an authorization bypass vulnerability in Livewire components that enforce authorization only at the route level, not within component lifecycle methods. Attackers with a valid authenticated session can replay signed component snapshots via POST /livewire/update to invoke protected methods and escalate privileges, including creating OAuth clients, minting personal access tokens, and accessing sensitive admin data.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 19.8%
CVSS Severity
CVSS v3 Score 6.4


Contact Us

Shodan ® - All rights reserved