PT-2026-70901 · Grokability+2 · Snipe-It

CVE-2026-19579

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Snipe-IT versions prior to 8.6.0
Description An authorization bypass occurs due to an insecure direct object reference in the asset checkout-request cancellation endpoint. The system reads cancel by admin and requestingUser values from user-controlled URL path segments without performing server-side authorization checks. Consequently, an authenticated user with low privileges can provide a non-empty cancel by admin value to bypass ownership checks and cancel pending checkout requests belonging to other users. Since asset and user identifiers are sequential integers, these can be enumerated to cancel all pending checkout requests, disrupting the asset-request workflow.
Recommendations Update to version 8.6.0.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19579

Affected Products

Snipe-It