CVE-2026-86759
Undergoing Analysis Undergoing Analysis - In Progress

Snipe-IT Asset Reassignment via Unauthorized POST Endpoint

Vulnerability report for CVE-2026-86759, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-20

Assigner: VulnCheck

Description

Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail entries, compromising inventory integrity and accountability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-20
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
snipe-it snipe-it to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Snipe-IT versions before 8.7.0. The POST /hardware/history endpoint lacks proper authorization checks, allowing any authenticated user to reassign assets and modify audit logs by submitting a malicious CSV file. The endpoint updates asset ownership without enforcing admin or superuser permissions, bypassing normal policies and company scoping in multi-tenant setups.

Detection Guidance

Check Snipe-IT version with: curl -s https://your-snipe-it-url.com/api/v1/about | grep version. If version is below 8.7.0, the system is vulnerable. Monitor web server logs for POST /hardware/history requests from non-admin users.

Impact Analysis

Attackers can reassign assets across companies, compromising inventory integrity. They can also inject fraudulent audit trail entries, falsely attributing changes to their user account. This undermines accountability and allows unauthorized modifications to asset ownership and history.

Compliance Impact

This vulnerability compromises audit trail integrity and accountability, which are critical for compliance with GDPR and HIPAA. Fraudulent audit logs could lead to inaccurate records, potentially violating data integrity and accountability requirements under these regulations.

Mitigation Strategies

Upgrade Snipe-IT to version 8.7.0 or later immediately. Block POST /hardware/history endpoint at the web server or WAF level. Temporarily add authorization check in AssetsController::postImportHistory as a workaround.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86759. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart