CVE-2026-86761 PUBLISHED

snipe-it 8.6.3 before 8.7.0 Authorization Bypass via print endpoints

Assigner: VulnCheck
Reserved: 08.09.2026 Published: 09.09.2026 Updated: 09.09.2026

snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to retrieve related users, assets, accessories, consumables, and components regardless of their individual model permissions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor grokability
Product snipe-it
Versions Default: unaffected
  • affected from 8.6.3 to 8.7.0 (excl.)
  • Version 8.7.0 is unaffected

References

Problem Types

  • Authorization Bypass Through User-Controlled Key CWE