CVE-2026-86761
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to retrieve related users, assets, accessories, consumables, and components regardless of their individual model permissions.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| grokability | snipe-it | 8.6.3 < 8.7.0 | affected |
| grokability | snipe-it | 8.7.0 | unaffected |
Weaknesses
- CWE-639: Authorization Bypass Through User-Controlled Key
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: partial
Additional References
References
- https://github.com/grokability/snipe-it/security/advisories/GHSA-cg5w-9662-73vx
- https://github.com/grokability/snipe-it/commit/7865bc56e372447631b6c0d6eb6774faf896553a
- https://www.vulncheck.com/advisories/snipe-it-8.6.3-before-8.7.0-authorization-bypass-via-print-endpoints
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.