Improper Input Validation in Snipe-IT Affects Asset Management
CVE-2026-86768
5.3MEDIUM
What is CVE-2026-86768?
Snipe-IT versions prior to 8.7.0 are susceptible to an improper input validation vulnerability in the API checkout endpoints. This issue allows authenticated users with proper checkout permissions to exploit the soft-deleted status of user, asset, or location IDs. By submitting POST requests to hardware, component, or consumable checkout endpoints with these IDs, attackers can create orphaned references that compromise the integrity of the asset ledger and corrupt audit trails. This vulnerability can lead to significant challenges in inventory management and tracking.
Affected Version(s)
snipe-it 8.6.3 < 8.7.0
snipe-it 8.7.0
