CVE-2026-86769
Undergoing Analysis Undergoing Analysis - In Progress

Improper Ownership Management in Snipe-IT Consumables Checkout

Vulnerability report for CVE-2026-86769, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-20

Assigner: VulnCheck

Description

Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with consumables.checkout permission can perform checkouts that result in misattributed audit trail entries in the consumables_users pivot table, obscuring which operator performed the action.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-20
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
snipe-it snipe-it to 8.7.0 (exc)
grokability snipe-it to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-282 The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86769 is an improper ownership management vulnerability in Snipe-IT versions before 8.7.0. It affects the consumables checkout API endpoint where the system records the checkout target user's ID instead of the authenticated caller's ID in the created_by column. This misattribution obscures which operator performed the action in audit trails.

Detection Guidance

To detect this vulnerability, review audit logs for inconsistencies in the consumables_users pivot table where the created_by field does not match the authenticated API caller. Check API call logs for POST requests to /api/v1/consumables/{id}/checkout and compare the user IDs in created_by with the actual authenticated user.

Impact Analysis

Authenticated attackers with consumables.checkout permission can exploit this to misattribute actions in the audit trail. This could lead to confusion about who performed specific actions, potentially hiding malicious activity or making it harder to trace accountability for consumable checkouts.

Compliance Impact

This vulnerability could impact compliance by compromising audit trail integrity. Regulations like GDPR and HIPAA require accurate logging of user actions for accountability and non-repudiation. Misattributed actions may fail to meet these requirements, potentially leading to compliance violations.

Mitigation Strategies
  • Upgrade Snipe-IT to version 8.7.0 or later to apply the official fix that corrects the created_by field to use auth()->id().
  • Temporarily rely on the action_logs stream for accurate audit data until the upgrade is completed.
  • Apply a SQL reconciliation query to retroactively correct historical pivot rows if needed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86769. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart