CVE-2026-86755
Undergoing Analysis Undergoing Analysis - In Progress

Authentication Bypass via Laravel Passport in Snipe-IT

Vulnerability report for CVE-2026-86755, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middleware, without the self.api permission gate that Snipe-IT enforces on its own token endpoints (/account/api and /api/v1/account/personal-access-tokens). Any user with a valid web session and the corresponding CSRF token can POST to /oauth/personal-access-tokens and mint a long-lived bearer token for their own account, even when an administrator has denied the self.api permission. The issued token is still subject to existing per-endpoint authorization policies, so this is not a privilege escalation; it defeats the administrative control intended to block API/scripted access at the user's own permission level. Fixed in 8.7.0 (commit 3f74b8c), which registers overriding routes wrapped in the can:self.api middleware.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
snipe-it snipe-it 8.7.0
snipe-it snipe-it From 4.2.0 (inc) to 8.6.3 (inc)
grokability snipe-it From 4.2.0 (inc) to 8.6.3 (inc)
grokability snipe-it 8.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Snipe-IT versions 4.2.0 through 8.6.3. It involves a permission bypass where Laravel Passport's auto-registered personal-access-token routes lack the self.api permission gate enforced on Snipe-IT's own token endpoints. An authenticated user with a valid web session can create long-lived API tokens via POST to /oauth/personal-access-tokens, bypassing admin controls that restrict API access.

Detection Guidance

Check if your Snipe-IT version is between 4.2.0 and 8.6.3 by running: curl -s https://your-snipe-it-url.com | grep -i version. If vulnerable, inspect network traffic for POST requests to /oauth/personal-access-tokens endpoints from authenticated users.

Impact Analysis

An attacker with a valid web session could mint API tokens for their account, enabling scripted or automated access to Snipe-IT's API even if the self.api permission is disabled. This bypasses administrative restrictions on API usage for individual users but does not escalate privileges.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by allowing unauthorized users to create long-lived API tokens, potentially enabling unauthorized access to sensitive data. If an administrator has restricted API access via the self.api permission, this bypass could violate access control requirements under these regulations.

Mitigation Strategies

Upgrade Snipe-IT to version 8.7.0 or later immediately. If upgrading is not possible, restrict access to /oauth/personal-access-tokens endpoints via web server configuration or firewall rules until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86755. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart