Authorization Bypass in Snipe-IT by Snipe
CVE-2026-19579

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-19579?

An authorization bypass vulnerability exists in Snipe-IT prior to version 8.6.0 which allows authenticated low-privileged users to manipulate checkout requests. The issue occurs in the asset checkout-request cancellation endpoint where user-controlled URL parameters are improperly validated. Attackers can exploit this by supplying values in the URL to bypass ownership checks of pending requests, potentially allowing them to cancel other users' checkout requests. This leads to disruptions in the asset-request workflow due to the predictable sequence of user and asset identifiers. This vulnerability has been addressed in Snipe-IT version 8.6.0.

Affected Version(s)

Snipe-IT 0 < 8.6.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Apostolos Karampelas with Tenable
.