Security Advisory

CVE-2026-55481

4.8
MEDIUM

Vulnerability Description

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related branding color settings inside a CSS style block with HTML escaping that is insufficient for the CSS context, allowing a superadmin to inject arbitrary CSS that affects authenticated users on subsequent page loads when Content Security Policy is disabled. This issue is fixed in version 8.6.2.
Published Date July 10, 2026
Official Source NIST NVD Advisory