Security Advisory
CVE-2026-55481
4.8
MEDIUM
Vulnerability Description
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin to inject arbitrary CSS that affects authenticated users on subsequent page loads when Content Security Policy is disabled. This issue is fixed in version 8.6.2.
Published Date
July 10, 2026
Official Source
NIST NVD Advisory