PT-2026-89034 · Git+1 · Snipe-It

·

CVE-2026-86765

·

Published

2026-09-09

·

Updated

2026-09-09

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset update endpoint. Authenticated users with edit permission but explicitly denied checkout permission can reassign assets, bypass check-in procedures, and alter custody records by submitting assigned user, assigned asset, or assigned location parameters to PATCH /api/v1/hardware/{id}.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86765
GHSA-6G2G-83PC-6365

Affected Products

Snipe-It