Permission Bypass in Snipe-IT Affects Hardware Component Access
CVE-2026-86764
7.1HIGH
What is CVE-2026-86764?
Snipe-IT versions up to 8.6.4 exhibit a security flaw where the permissions for accessing hardware components are not properly enforced. Specifically, the API endpoint allowing access to details about assigned components does not require the components.view permission for authenticated users, only assets.view on the parent asset. This oversight allows users with limited permissions to enumerate protected component data, including IDs, names, quantities, and notes, leading to potential disclosures of sensitive information. The vulnerability has been addressed in version 8.7.0.
Affected Version(s)
snipe-it 8.6.4 < 8.7.0
snipe-it 8.7.0
