Permission Bypass in Snipe-IT Affects Hardware Component Access
CVE-2026-86764

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-86764?

Snipe-IT versions up to 8.6.4 exhibit a security flaw where the permissions for accessing hardware components are not properly enforced. Specifically, the API endpoint allowing access to details about assigned components does not require the components.view permission for authenticated users, only assets.view on the parent asset. This oversight allows users with limited permissions to enumerate protected component data, including IDs, names, quantities, and notes, leading to potential disclosures of sensitive information. The vulnerability has been addressed in version 8.7.0.

Affected Version(s)

snipe-it 8.6.4 < 8.7.0

snipe-it 8.7.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ashrexon
.