CVE-2026-44833

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
26/05/2026
Last modified:
26/05/2026

Description

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is fixed in 8.4.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:* 8.4.1 (excluding)