PT-2026-70901 · Grokability+2 · Snipe-It
CVE-2026-19579
·
Published
2026-08-11
·
Updated
2026-08-11
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Snipe-IT versions prior to 8.6.0
Description
An authorization bypass occurs due to an insecure direct object reference in the asset checkout-request cancellation endpoint. The system reads
cancel by admin and requestingUser values from user-controlled URL path segments without performing server-side authorization checks. Consequently, an authenticated user with low privileges can provide a non-empty cancel by admin value to bypass ownership checks and cancel pending checkout requests belonging to other users. Since asset and user identifiers are sequential integers, these can be enumerated to cancel all pending checkout requests, disrupting the asset-request workflow.Recommendations
Update to version 8.6.0.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snipe-It