9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component
AI Analysis
Insecure Permissions vulnerability allowing remote arbitrary code execution
Basic Information
ID
CVE-2026-37709
Source
mitre
Published
May 7, 2026 at 00:00
Modified
May 7, 2026 at 17:39
Affected Product
Vendor
grokability
Product
snipe-it
Version
8.4.0 and before
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
grokability
Product
snipe-it
Version
8.4.0 and before