Broken Access Control in Snipe-IT by Grokability
CVE-2026-86773
5.3MEDIUM
What is CVE-2026-86773?
Snipe-IT versions up to 8.6.3 exhibit a vulnerability due to inadequate object-level authorization in critical endpoints, including updateLicense and storeModel for Predefined Kits. An authenticated user with limited permissions can exploit this flaw to attach unauthorized items, such as Licenses or Accessories, to a Predefined Kit, despite being restricted from directly accessing these items. This issue compromises the integrity of user permissions and exposes sensitive information to unauthorized users. The vulnerability was addressed in version 8.7.0.
Affected Version(s)
snipe-it 8.6.3 < 8.7.0
snipe-it 8.7.0
