PT-2026-89038 · Git+1 · Snipe-It

·

CVE-2026-86769

·

Published

2026-09-09

·

Updated

2026-09-09

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created by column instead of the authenticated caller's id. Authenticated attackers with consumables.checkout permission can perform checkouts that result in misattributed audit trail entries in the consumables users pivot table, obscuring which operator performed the action.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86769
GHSA-X9P8-VVC5-Q754

Affected Products

Snipe-It