CVE-2026-86735: snipe-it before 8.7.0 SSRF via IPv6 transition address bypass

Published Sep 8, 2026
·
Updated

snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets. Attackers with super-admin privileges can configure webhook URLs using NAT64, 6to4, or Teredo transition addresses to bypass SSRF guards and access internal services or cloud metadata endpoints.

Affected Software

1 affected component
Snipe-IT Snipe-IT<8.7.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade snipe-it to a version that resolves this vulnerability.

    Fixed in 8.7.0
  2. Compensating control

    Until upgraded, review and restrict super-admin capability to configure webhook URLs, since attackers with super-admin privileges can supply NAT64, 6to4, or Teredo transition addresses to bypass SSRF guards.

Event History

Sep 8, 2026
CVE Published
via MITRE·03:14 PM
Data Sourced
via MITRE·03:14 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Exploitation requires super-admin privileges in Snipe-IT. The attacker must be able to configure a webhook URL.

2

What kind of target can an attacker reach through the bypass?

An attacker can use NAT64, 6to4, or Teredo IPv6 transition addresses that encode private IPv4 targets. This can enable requests to internal services or cloud metadata endpoints.

3

Which deployments are affected?

Snipe-IT versions before 8.7.0 are affected. The issue is in ExternalUrl validation used for webhook URLs.

4

What is the immediate mitigation if upgrading is not possible?

The provided information does not specify a workaround. Restrict super-admin access and review webhook URL configuration, particularly for NAT64, 6to4, and Teredo addresses.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203