CVE-2026-86744
Analyzed Analyzed - Analysis Complete

Race Condition in Snipe-IT Asset Checkout

Vulnerability report for CVE-2026-86744, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-18

Assigner: VulnCheck

Description

Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) contain a race condition in the asset checkout paths. Api\AssetsController::checkout() and Assets\AssetCheckoutController::store() call Asset::availableForCheckout() outside the mutation path and then invoke Asset::checkOut() without taking a row lock or re-checking availability, so two concurrent checkout requests for the same available asset can both observe it as available and both commit. This produces duplicate checkout-history rows, a doubled checkout_counter, and two CheckoutableCheckedOut events for a single-assignment asset, corrupting the audit trail and utilization/reconciliation reporting; the asset's final assigned_to remains singular, so the visible assignment stays intact. Exploitation requires an authenticated session holding the assets.checkout permission (or superuser) and precise concurrent timing. Fixed in 8.7.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-18
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
snipeitapp snipe-it to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-362 The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a race condition in Snipe-IT versions 8.6.3 and earlier. It occurs in the asset checkout process where two concurrent requests for the same available asset can both pass an availability check and proceed to checkout. This leads to duplicate checkout history entries, an inflated checkout counter, and multiple events for a single assignment, corrupting the audit trail and utilization reports.

Detection Guidance

Detecting this race condition requires monitoring for duplicate checkout history entries or inflated checkout counters for the same asset. Check Snipe-IT logs for multiple CheckoutableCheckedOut events for a single assignment. Review database tables like asset_checkout_history and assets for inconsistencies in checkout_counter values.

Impact Analysis

The impact includes corrupted audit trails and inaccurate utilization or reconciliation reporting due to duplicate entries and inflated counters. The asset's final assignment remains correct, but the data integrity of historical records is compromised. Exploitation requires an authenticated session with specific permissions and precise timing.

Compliance Impact

This vulnerability corrupts audit trails and utilization reports by creating duplicate checkout history entries and inflating counters. This could violate compliance requirements for accurate record-keeping and data integrity under standards like GDPR (data accuracy principle) and HIPAA (audit controls).

Mitigation Strategies

Upgrade Snipe-IT to version 8.7.0 or later immediately to apply the fix. If upgrading is not possible, restrict concurrent checkout requests by limiting user sessions or implementing rate limiting for checkout operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86744. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart