Authorization Bypass in Snipe-IT by Snipe
CVE-2026-19579
5.3MEDIUM
What is CVE-2026-19579?
An authorization bypass vulnerability exists in Snipe-IT prior to version 8.6.0 which allows authenticated low-privileged users to manipulate checkout requests. The issue occurs in the asset checkout-request cancellation endpoint where user-controlled URL parameters are improperly validated. Attackers can exploit this by supplying values in the URL to bypass ownership checks of pending requests, potentially allowing them to cancel other users' checkout requests. This leads to disruptions in the asset-request workflow due to the predictable sequence of user and asset identifiers. This vulnerability has been addressed in Snipe-IT version 8.6.0.
Affected Version(s)
Snipe-IT 0 < 8.6.0
