Business Logic Bypass Vulnerability in Snipe-IT by Grokability
CVE-2026-86753
5.3MEDIUM
What is CVE-2026-86753?
In Snipe-IT versions before 8.7.0, a business logic bypass vulnerability exists that allows authenticated users to exploit the POST /account/request/asset_model/{modelId} endpoint. This flaw enables users to create checkout requests for asset models marked as non-requestable, circumventing administrative controls. Proper validation of the requestable flag is not enforced, which poses a significant risk for asset mismanagement and unauthorized access.
Affected Version(s)
snipe-it 0 < 8.7.0
snipe-it 8.7.0
