CVE-2026-86765
Undergoing Analysis Undergoing Analysis - In Progress

Snipe-IT Privilege Escalation via Asset Reassignment

Vulnerability report for CVE-2026-86765, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset update endpoint. Authenticated users with edit permission but explicitly denied checkout permission can reassign assets, bypass check-in procedures, and alter custody records by submitting assigned_user, assigned_asset, or assigned_location parameters to PATCH /api/v1/hardware/{id}.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
snipe-it snipe-it to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86765 is an authorization bypass flaw in Snipe-IT versions before 8.7.0. Authenticated users with edit permissions but denied checkout permissions can exploit the asset update endpoint to reassign assets, bypass check-in procedures, and alter custody records by submitting specific parameters like assigned_user or assigned_location.

Detection Guidance

Check Snipe-IT version with: curl -s https://your-snipe-it-url.com/api/v1/about | grep version. If version is below 8.7.0, the system is vulnerable. Monitor API logs for PATCH requests to /api/v1/hardware/{id} containing assigned_user, assigned_asset, or assigned_location parameters from users without checkout permissions.

Impact Analysis

This vulnerability allows attackers to reassign assets between users, assign non-deployable assets, manipulate checkout counters and timestamps, and corrupt the asset custody audit trail. It undermines financial controls, compliance reporting, and regulatory evidence by bypassing required workflows.

Compliance Impact

The vulnerability can impact compliance by enabling unauthorized asset transfers and falsified custody records, which may violate audit requirements, financial controls, and regulatory evidence standards. It undermines separation of duties and data integrity, potentially leading to non-compliance with GDPR, HIPAA, or other frameworks requiring accurate asset tracking and access controls.

Mitigation Strategies

Upgrade Snipe-IT to version 8.7.0 or later immediately. Review user permissions to ensure users with edit rights do not have checkout permissions revoked. Audit recent asset assignments via admin panel to identify unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86765. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart