CVE-2026-86772 | grokability Snipe-IT up to 8.6.3 My Assets Page formattedNameLink cross site scripting

SecurityVulns

A vulnerability described as problematic has been identified in grokability Snipe-IT up to 8.6.3. The affected element is the function DepartmentPresenter::formattedNameLink of the component My Assets Page. Executing a manipulation can lead to cross site scripting.

This vulnerability is registered as CVE-2026-86772. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More