CVE WATCH / VULNERABILITY DETAIL

CVE-2026-63498

HIGHCVSS 8.7NVD feed

Published 24 September 2026 · tracked since 25 September 2026

Description

Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML and XSLT attachments and request them with the inline=true parameter. The app/Http/

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-63498 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-63498

HIGHCVSS 8.7NVD feed

Published 24 September 2026 · tracked since 25 September 2026

Description

Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML and XSLT attachments and request them with the inline=true parameter. The app/Http/

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]