PKSA-35bw-hh2v-5kbx Security Advisory
-
[MEDIUM] Snipe-IT's TOTP is Brute-Forceable Due to Missing Rate Limiting on `POST /two-factor`
PKSA-35bw-hh2v-5kbx CVE-2026-49870 GHSA-mr8g-2mj4-pcq2
Affected package: snipe/snipe-it
Affected version: <8.6.0
Reported by:
GitHub