CVE-2026-86736
Analyzed Analyzed - Analysis Complete

Incorrect Calculation in Snipe-IT Asset Checkout Counter

Vulnerability report for CVE-2026-86736, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-19

Assigner: VulnCheck

Description

snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attackers can repeatedly call cancel endpoints without active requests to drive the counter negative, or submit duplicate checkout requests to inflate the counter, misrepresenting pending demand in the admin queue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-19
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
snipeitapp snipe-it to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-682 The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86736 is an incorrect calculation vulnerability in the Snipe-IT asset management system before version 8.7.0. It allows authenticated users to manipulate the assets.requests_counter by submitting duplicate checkout requests or canceling non-existent requests. This can either inflate or drive the counter negative, misrepresenting pending demand in the admin queue.

Detection Guidance

Check Snipe-IT logs for duplicate checkout requests or cancellations without active requests. Monitor the assets.requests_counter field for unexpected negative values or rapid fluctuations. Review admin queue and requestable-assets index for misrepresented pending demand.

Impact Analysis

This vulnerability can lead to incorrect reporting of asset demand, causing administrators to see false pending requests. It may also allow users to exploit the system by artificially increasing or decreasing request counts, potentially disrupting asset management workflows.

Mitigation Strategies

Upgrade to Snipe-IT version 8.7.0 or later immediately. Review and audit all recent checkout and cancellation requests for anomalies. Implement input validation to prevent duplicate submissions and invalid cancellations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86736. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart