Race Condition in Snipe-IT Consumable Checkout API Affects Grokability
CVE-2026-86766

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-86766?

Snipe-IT versions up to and including 8.6.3 are susceptible to a race condition within the consumable checkout API endpoint. This vulnerability allows authenticated users, authorized to check out consumables, to exploit concurrent requests. When two requests for the same consumable are made simultaneously, both can pass the initial availability check. As a result, the system does not prevent over-allocation of stock, leading to negative inventory levels. This issue is resolved in version 8.7.0 through a transactional lock and re-validation mechanism.

Affected Version(s)

snipe-it 8.6.3 < 8.7.0

snipe-it 8.7.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nullbenny
.