Race Condition in Snipe-IT Consumable Checkout API Affects Grokability
CVE-2026-86766
7.1HIGH
What is CVE-2026-86766?
Snipe-IT versions up to and including 8.6.3 are susceptible to a race condition within the consumable checkout API endpoint. This vulnerability allows authenticated users, authorized to check out consumables, to exploit concurrent requests. When two requests for the same consumable are made simultaneously, both can pass the initial availability check. As a result, the system does not prevent over-allocation of stock, leading to negative inventory levels. This issue is resolved in version 8.7.0 through a transactional lock and re-validation mechanism.
Affected Version(s)
snipe-it 8.6.3 < 8.7.0
snipe-it 8.7.0
