CVE-2026-86768
Undergoing Analysis Undergoing Analysis - In Progress

Snipe-IT Asset Ledger Corruption via Soft-Deleted ID Abuse

Vulnerability report for CVE-2026-86768, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: VulnCheck

Description

Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets. Attackers can submit POST requests to hardware, component, or consumable checkout endpoints with soft-deleted user, asset, or location IDs to create orphaned references that corrupt the asset ledger and audit trails.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
snipe-it snipe-it to 8.7.0 (exc)
grokability snipe-it to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Snipe-IT before version 8.7.0 has a flaw where API checkout endpoints do not properly validate if a target (user, asset, or location) is soft-deleted. Authenticated users with checkout permissions can bind live inventory to these trashed targets by submitting POST requests with soft-deleted IDs. This creates orphaned references that corrupt the asset ledger and audit trails.

Detection Guidance

Check Snipe-IT API logs for POST requests to /api/v1/hardware/{id}/checkout, /api/v1/components/{id}/checkout, or /api/v1/consumables/{id}/checkout with soft-deleted IDs. Look for orphaned references in asset ledgers or audit trails that indicate corrupted inventory bindings.

Impact Analysis

This vulnerability allows attackers to corrupt inventory records by linking live assets to deleted targets. It can disrupt audit trails, cause data inconsistencies in the asset ledger, and potentially affect cleanup workflows. The impact includes integrity and availability issues but does not affect confidentiality.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by corrupting audit trails and asset ledgers. Soft-deleted records may remain referenced in live inventory, violating data retention and integrity requirements. For GDPR, this affects accountability and lawful processing. For HIPAA, it compromises audit controls and integrity of medical asset tracking.

Mitigation Strategies

Upgrade Snipe-IT to version 8.7.0 or later to patch the improper input validation flaw. If immediate upgrade is not possible, restrict API checkout permissions to trusted users and monitor for suspicious POST requests to affected endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86768. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart