Authorization Flaw in Snipe-IT Asset Management System by Grokability
CVE-2026-86737
5.3MEDIUM
What is CVE-2026-86737?
Snipe-IT versions prior to 8.7.0 contain a significant authorization flaw in the GET /hardware/{asset}/barcode endpoint. This vulnerability allows authenticated attackers to bypass authorization checks, enabling them to manipulate asset IDs effectively. As a consequence, attackers can retrieve barcodes and enumerate asset tags across different tenants, including sensitive information related to soft-deleted assets and assets owned by other companies. This exposure presents data leakage risks and potential exploitation in multi-tenant environments.
Affected Version(s)
snipe-it 0 < 8.7.0
snipe-it 8.7.0
