<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T06:21:15.484716+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-356522</id>
    <title>EUVD-2026-356522</title>
    <updated>2026-10-10T06:21:15.536980+00:00</updated>
    <content>EUVD-2026-356522</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-356522"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49976</id>
    <title>fkie_cve-2026-49976</title>
    <updated>2026-10-10T06:21:15.537016+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update mode to overwrite the email address of a non-admin user and then request a password reset to take over that account. app/Importer/UserImporter.php applies the canEditAuthFields gate by unsetting username, email, password, and activated on the model, but app/Importer/ItemImporter.php sanitizeItemForUpdating() rebuilds the update array from the raw CSV row in $this-&gt;item, restoring the unauthorized values. The app/Http/Controllers/ImportController.php import path checks import permission but does not require users.edit. This issue is fixed in version 8.6.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-49976"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p68w-rgmg-3c2v</id>
    <title>GHSA-p68w-rgmg-3c2v — Snipe-IT Vulnerable to User Account Escalation via CSV Import</title>
    <updated>2026-10-10T06:21:15.537052+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: snipe/snipe-it</p>
<p>### Impact
The CSV user import in update mode bypasses user-edit authorization. A user with only the `import` permission can overwrite any non-admin user's email by uploading a CSV, then trigger a password reset to take over the account.</p>
<p>`UserImporter.php` checks the `canEditAuthFields` gate and tries to strip auth fields from the model:</p>
<p>```php
// app/Importer/UserImporter.php:107-114
if (Auth::check() &amp;&amp; (! Gate::allows('canEditAuthFields', $user))) {
    unset($user-&gt;username);
    unset($user-&gt;email);
    unset($user-&gt;password);
    unset($user-&gt;activated);
}
$user-&gt;update($this-&gt;sanitizeItemForUpdating($user));
```</p>
<p>The `unset()`s operate on the model, but `sanitizeItemForUpdating()` rebuilds its array from `$this-&gt;item` (the raw CSV row), not from the model:</p>
<p>```php
// app/Importer/ItemImporter.php:135-149
protected function sanitizeItemForStoring($model, $updating = false)
{
    $item = collect($this-&gt;item);                  // CSV data, not model attributes
    $item = $item-&gt;only($model-&gt;getFillable());
    if ($updating) {
        $item = $item-&gt;reject(fn($v) =&gt; empty($v));
    }
    return $item-&gt;toArray();
}
```</p>
<p>The attacker's CSV values pass through untouched.</p>
<p>For non-admin attacker vs. non-admin, non-superuser target, the gate returns `true` at `AuthServiceProvider.php:137`, so the `unset()` block never executes. The entire import path checks only `$this-&gt;authorize('import')` (`ImportController.php:196`); no `users.edit` check anywhere. The normal API route…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p68w-rgmg-3c2v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2051</id>
    <title>WID-SEC-W-2026-2051 — Snipe-IT: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-10T06:21:15.537101+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Snipe-IT ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2051"/>
  </entry>
</feed>
