HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-44833 — Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redir...

·Source: NIST NVD

Updated:

Executive Summary

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is fixed in 8.4.1.

Analysis

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is fixed in 8.4.1. CVSS Score: 5.9. Published: 2026-05-26T20:16:20.317.

Indicators of Compromise (1)

CVE (1)
CVE-2026-44833
Source Attribution

Originally published by NIST NVD on May 26, 2026. Verified by: NIST.

Related Threats