Vulnerabilities
7,717 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-86762 | Missing authorization in Snipe-IT lets deactivated users keep full API access Snipe-IT before 8.7.0 fails to apply the CheckUserIsActivated middleware to its API middleware group and does not revoke a user's Passport personal access tokens when that user is deactivated (CWE-862). An attacker or former employee holding an existing API token for a deactivated account can therefore continue calling the REST API — reading and modifying assets, users, licenses, and other records — at the account's prior permission level until the token expires, even though web login is correctly blocked. If the deactivated account retains user-management permissions, it can even reactivate itself through the API, permanently undoing the deactivation control. All Snipe-IT deployments running a version before 8.7.0 in which deactivated users held issued API tokens are affected. There is no evidence of in-the-wild exploitation, no public proof-of-concept, and the issue is not in the CISA KEV catalog. Do: Upgrade to Snipe-IT 8.7.0 or later. As an interim mitigation, manually revoke the Passport personal access tokens of any deactivated users (delete their oauth_access_tokens entries) and audit recently deactivated accounts for API activity, including unexpected self-reactivation or changes made at their former permission level. | 8.6 group max | <1% | PoC |
| moderate≈10,000–100,000 self-hosted instances (widely adopted open-source IT asset-management tool; most run on internal networks rather than internet-exposed) | |
| CVE-2026-87084 +1 in the same advisory: …87088 | Server-Side Request Forgery (SSRF) in Tanium Enforce Tanium has addressed a server-side request forgery (SSRF, CWE-918) vulnerability in its Enforce product, in which the server can be induced to issue requests to attacker-chosen destinations. Per the CVSS vector, exploitation requires low-privileged (authenticated) access over the network and no user interaction, and the changed scope (S:C) indicates a forged request can cross a trust boundary to reach other internal systems or services. An attacker gains a high degree of confidentiality impact — typically the ability to probe or retrieve data from internal networks, cloud metadata endpoints, or otherwise inaccessible services — with no integrity or availability impact indicated. Any organization operating a Tanium Enforce deployment is affected, particularly where untrusted or low-trust users can authenticate to the product's interface or API. There is no known public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at a low 0.2%, so exploitation is not currently observed. Do: Update Tanium Enforce to the patched release identified in Tanium's advisory, since the affected/fixed version numbers are not included in this data. Limit which low-privileged users can authenticate to Enforce and review outbound network access from the Enforce server (e.g., egress rules and access to internal services or cloud metadata endpoints) to reduce SSRF blast radius. No public PoC or in-the-wild exploitation is known, so patching at the next normal maintenance window is a reasonable cadence for most defenders. | 7.7 group max | <1% |
| moderatelikely on the order of 1,000–10,000 Enforce server deployments (exact counts not published) | ||
| CVE-2026-87030 | Authenticated Path Traversal in Tanium Comply Tanium Comply, the compliance-assessment module of the Tanium platform, contained a path traversal vulnerability (CWE-22) that Tanium has now patched. An attacker who holds low-privileged credentials on the system can submit crafted paths that escape the intended directory boundary; because the CVSS scope is 'changed', the traversal can cross into a neighboring security scope, yielding a high integrity impact (unauthorized file modification) and a low availability impact, with no confidentiality loss. The flaw is triggered over the network by authenticated, low-privilege input rather than by unauthenticated requests or user interaction. Any organization running the Tanium Comply module is in scope for the fix. There is no evidence of exploitation so far: the issue is not in CISA's KEV and no public proof-of-concept is known. Do: Deploy the Tanium-published update for Comply as soon as possible, confirming the fixed version in Tanium's advisory since no specific patched version is given in the disclosure data. Because exploitation requires low-privileged authenticated access, review which accounts can reach Comply and monitor for unexpected file modifications in or around the Comply installation. Re-run or verify compliance scans after patching to confirm no artifacts were tampered with. | 8.5 group max | <1% |
| unknown (plausibly thousands of enterprise deployments of the Comply module) |