CVE-2026-86764
Undergoing Analysis Undergoing Analysis - In Progress

Sensitive Component Enumeration in Snipe-IT

Vulnerability report for CVE-2026-86764, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-20

Assigner: VulnCheck

Description

Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only assets.view on the parent asset before returning linked component details; the components.view check is applied only to the response's available_actions.view flag and not to the returned data. As a result, an authenticated user holding only assets.view can enumerate component IDs, names, assigned quantities, and notes that are otherwise protected β€” the direct GET /api/v1/components/<id> endpoint correctly returns 403 Forbidden for such users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-20
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
snipe-it snipe-it to 8.6.4 (inc)
snipe-it snipe-it 8.7.0
snipe-it snipe-it to 8.6.9 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86764 is a permission bypass vulnerability in Snipe-IT versions 8.6.4 through 8.6.9. It allows authenticated users with only assets.view permission to enumerate sensitive component details via the GET /api/v1/hardware/<asset-id>/assigned/components endpoint. The endpoint fails to enforce components.view permission on the returned data, exposing component IDs, names, assigned quantities, and notes.

Detection Guidance

To detect this vulnerability, check if your Snipe-IT instance is running a version prior to 8.7.0. Use the command: curl -s http://your-snipe-it-url/ | grep -i "version" or check the footer of the web interface for version details. Then verify if the endpoint GET /api/v1/hardware/<asset-id>/assigned/components returns component details for users with only assets.view permission.

Test with a user having assets.view but not components.view. If the endpoint returns component IDs, names, quantities, or notes, the system is vulnerable.

Impact Analysis

An attacker with authenticated access and only assets.view permission could exploit this to access restricted component information. This includes sensitive data like component IDs, names, quantities, and notes that should be protected. The impact is primarily on confidentiality, as data integrity and availability are not affected.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized access to sensitive data. GDPR requires protection of personal data, while HIPAA mandates safeguards for protected health information. Unauthorized exposure of component details may violate these regulations, potentially resulting in legal penalties and reputational damage.

Mitigation Strategies

Immediately upgrade Snipe-IT to version 8.7.0 or later to patch the vulnerability. If upgrading is not possible, restrict access to the vulnerable endpoint via network controls or API gateways until the upgrade is completed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86764. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart