CVE-2026-63493
Last modified
CVE-2026-63493 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-token API flow before completing the account's second-factor challenge because CheckForTwoFactor is enforced in the web middleware group but not the API middleware group.
Description
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-token API flow before completing the account's second-factor challenge because CheckForTwoFactor is enforced in the web middleware group but not the API middleware group. The advisory states that the resulting persistent API token can read and modify resources with the victim's permissions and, for an administrator, can reach the users/two_factor_reset endpoint. Resetting the administrator's enrolled second factor allows the password-holding attacker to enroll an attacker-controlled factor, take over the administrator's web account, and lock out the legitimate user. The token does not create a web session, but it provides broad API access while the same browser session remains blocked at the two-factor page. This vulnerability is fixed in 8.7.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| grokability | snipe-it | < 8.7.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-63493?
How severe is CVE-2026-63493?
How do I fix CVE-2026-63493?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6347Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 1…7.6
- CVE-2026-63472Vendure is an open-source headless commerce platform. Prior …9.1
- CVE-2026-6348WinMatrix agent developed by Simopro Technology has a Missin…9.3
- CVE-2026-63481Hurl is a command line tool that runs and tests HTTP request…6.9
- CVE-2026-6349The iSherlock developed by HGiga has an OS Command Injecti…9.8
- CVE-2026-63490Handlebars.java provides logic-less and semantic Mustache te…7.5
- CVE-2026-63495Libevent is an event notification library. From 2.2.0-alpha-…7.5
- CVE-2026-63498Snipe-IT is an IT asset/license management system. Prior to …8.7
- CVE-2026-6350MailGates/MailAudit developed by Openfind has a Stack-based …9.8
- CVE-2026-63506Tina is a headless content management system. Prior to @tina…8.8
- CVE-2026-63508Missing authentication for critical function in Microsoft Pl…10
- CVE-2026-63509Relative path traversal in Microsoft Fabric allows an author…8.8
Are you affected by CVE-2026-63493?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
