
🚨 Critical - Snipe-IT Insecure File Upload Permissions (CVE-2026-37709) A critical vulnerability in Snipe-IT allows remote attackers to execute arbitrary code via the UploadedFilesController. The API incorrectly authorized file uploads using "view" permissions instead of "write" permissions, enabling users with basic read access to upload malicious files and achieve Remote Code Execution (RCE). 👉 Affected: Snipe-IT < 8.4.1 | Upgrade to 8.4.1
Post summary
Snipe‑IT users are warned of a critical RCE flaw stemming from improper upload authorization; upgrading to version 8.4.1 resolves the vulnerability.

