Improper Restriction of Excessive Authentication Attempts in snipe-it - CVE-2026-49870
Published: June 9, 2026
snipe-it
Detailed vulnerability description
The vulnerability allows a remote user to bypass two-factor authentication and obtain a fully authenticated session.
The vulnerability exists due to improper access control in the POST /two-factor endpoint when processing TOTP verification requests. A remote user can submit unlimited TOTP guesses to bypass two-factor authentication and obtain a fully authenticated session.
If two-factor authentication is configured in optional mode, the account owner can disable two-factor authentication without OTP re-verification after login.