Authorization Bypass Vulnerability in Snipe-IT by Grokability
CVE-2026-86765

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-86765?

Snipe-IT prior to version 8.7.0 is susceptible to an authorization bypass vulnerability. This occurs when authenticated users with editing privileges can submit changes to asset parameters via the PATCH /api/v1/hardware/{id} endpoint, despite being denied checkout permissions. This flaw enables unauthorized reassignments of assets and manipulation of custody records, effectively bypassing the necessary check-in procedures designed to maintain asset accountability.

Affected Version(s)

snipe-it 8.6.3 < 8.7.0

snipe-it 8.7.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nullbenny
builtbybrayden
.