CVE-2026-86753
Analyzed Analyzed - Analysis Complete

Snipe-IT Asset Model Request Bypass

Vulnerability report for CVE-2026-86753, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint. Authenticated users can bypass administrative restrictions and create checkout requests for non-requestable asset models by submitting requests directly to the endpoint.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
snipeitapp snipe-it to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a business logic bypass vulnerability in Snipe-IT asset management software versions before 8.7.0. It allows authenticated users to request asset models that are explicitly marked as non-requestable by exploiting a flaw in the POST /account/request/asset_model/{modelId} endpoint. The server fails to validate the requestable flag for asset models, enabling users to bypass administrative restrictions and create checkout requests for restricted models.

Detection Guidance

To detect this vulnerability, check Snipe-IT versions before 8.7.0 by running commands like 'composer show snipe/snipe-it' or checking the version in the web interface. Monitor for unusual checkout requests for non-requestable asset models in the admin panel or database logs.

Impact Analysis

This vulnerability allows authenticated users to submit requests for non-requestable asset models, potentially spamming admin approval queues with unnecessary requests. While it doesn't automatically grant access to restricted assets, it undermines access control policies and creates extra administrative overhead for manual approval processes.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR or HIPAA as it does not involve unauthorized data access or disclosure. However, it could indirectly affect compliance by undermining access control policies, potentially leading to unauthorized asset requests that may require manual administrative review, increasing administrative burden and potential delays in approval processes.

Mitigation Strategies

Immediately upgrade Snipe-IT to version 8.7.0 or later. Review recent checkout requests for non-requestable asset models and revoke any unauthorized requests. Ensure the {itemType} route parameter is restricted to valid values to prevent further bypass attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86753. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart