CVE-2026-86742: Snipe-IT before 8.7.0 CSV Formula Injection via Asset Acceptance Report

Published Sep 9, 2026
·
Updated

Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export. ReportsController::postAssetAcceptanceReport builds the CSV by hand (stripping commas and joining rows manually) and, unlike the six sibling exports in the same controller, never applies League\Csv\EscapeFormula or honors the config('app.escapeformulas') setting. An authenticated low-privilege user with ordinary create/edit rights on any record whose free-text fields appear in the report (asset name/tag, company name, category, model, or assignee display name) can set such a field to a value beginning with =, +, -, @, tab, or CR. When a user with reports.view privileges requests the export (POST /reports/unacceptedassets) for a pending checkout acceptance referencing the poisoned record and opens the resulting CSV in Excel, LibreOffice Calc, or Google Sheets, the injected content is evaluated as a formula in the downloader's spreadsheet context, enabling data exfiltration (e.g., HYPERLINK/WEBSERVICE) or, on legacy Windows Excel configurations, DDE command execution. Fixed in 8.7.0.

Affected Software

1 affected component
Snipe-IT Snipe-IT<8.7.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Snipe-IT to a version that resolves this vulnerability.

    Fixed in 8.7.0

Event History

Sep 9, 2026
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue, and who is at risk when the CSV is opened?

An authenticated low-privilege user with ordinary create or edit rights can poison free-text fields that appear in the unaccepted-assets report. A user with reports.view privileges is exposed when they export a pending checkout acceptance referencing that record and open the CSV in a spreadsheet application.

2

Are default deployments affected?

Yes. The affected export does not apply formula escaping and does not honor the app.escape_formulas configuration setting, unlike sibling exports in the same controller.

3

What conditions are required for exploitation?

The attacker must be able to edit a relevant asset, company, category, model, or assignee display-name field and set it to a value beginning with =, +, -, @, a tab, or a carriage return. The poisoned record must be associated with a pending checkout acceptance, and a reports.view user must request POST /reports/unaccepted_assets and open the resulting CSV.

4

What can be done if upgrading is not immediately possible?

Restrict ordinary users from creating or editing records whose free-text fields appear in the report, and restrict access to the unaccepted-assets export to trusted users. Do not open exported CSV files in Excel, LibreOffice Calc, or Google Sheets until affected data has been reviewed for formula-prefixed values.

5

How can teams identify possible prior exposure?

Review pending checkout acceptance records and the associated asset name or tag, company, category, model, and assignee display-name fields for values beginning with =, +, -, @, tab, or carriage return. Also identify users who have requested the unaccepted-assets report and opened its CSV output.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203