Improper Input Validation in Snipe-IT Affects Asset Management
CVE-2026-86768

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-86768?

Snipe-IT versions prior to 8.7.0 are susceptible to an improper input validation vulnerability in the API checkout endpoints. This issue allows authenticated users with proper checkout permissions to exploit the soft-deleted status of user, asset, or location IDs. By submitting POST requests to hardware, component, or consumable checkout endpoints with these IDs, attackers can create orphaned references that compromise the integrity of the asset ledger and corrupt audit trails. This vulnerability can lead to significant challenges in inventory management and tracking.

Affected Version(s)

snipe-it 8.6.3 < 8.7.0

snipe-it 8.7.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

5h1kh4r
.