CVE-2026-55481

Severity CVSS v4.0:
MEDIUM
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
10/07/2026
Last modified:
14/07/2026

Description

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin to inject arbitrary CSS that affects authenticated users on subsequent page loads when Content Security Policy is disabled. This issue is fixed in version 8.6.2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:* 8.6.2 (excluding)