CVE-2026-37709 PUBLISHED

Assigner: mitre
Reserved: 06.04.2026 Published: 07.05.2026 Updated: 07.05.2026

Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component

Product Status

Vendor n/a
Product n/a
Versions
  • Version n/a is affected

References

Problem Types

  • n/a text