Authorization Bypass Vulnerability in Snipe-IT by Grokability
CVE-2026-86765
7.1HIGH
What is CVE-2026-86765?
Snipe-IT prior to version 8.7.0 is susceptible to an authorization bypass vulnerability. This occurs when authenticated users with editing privileges can submit changes to asset parameters via the PATCH /api/v1/hardware/{id} endpoint, despite being denied checkout permissions. This flaw enables unauthorized reassignments of assets and manipulation of custody records, effectively bypassing the necessary check-in procedures designed to maintain asset accountability.
Affected Version(s)
snipe-it 8.6.3 < 8.7.0
snipe-it 8.7.0
