HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-44833 — Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redir...
·Source: NIST NVD
Updated:
Executive Summary
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is fixed in 8.4.1.
Analysis
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is fixed in 8.4.1. CVSS Score: 5.9. Published: 2026-05-26T20:16:20.317.