Vulnerability Description
Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Snipeitapp | Snipe-It | < 8.4.1 |
Related Weaknesses (CWE)
References
- https://github.com/grokability/snipe-it/commit/676a9958895a77de340565e7a0b17ae74Patch
- https://github.com/grokability/snipe-it/security/advisories/GHSA-xg82-2hrv-hf64PatchVendor Advisory
FAQ
What is CVE-2026-37709?
CVE-2026-37709 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers...
How severe is CVE-2026-37709?
CVE-2026-37709 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-37709?
Check the references section above for vendor advisories and patch information. Affected products include: Snipeitapp Snipe-It.