CVE-2026-86761
Dashboard / Vulnerabilities / CVE-2026-86761
Summary: snipe-it 8.6.3 before 8.7.0 Authorization Bypass via print endpoints
Details: snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to retrieve related users, assets, accessories, consumables, and components regardless of their individual model permissions.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86761.json, https://github.com/grokability/snipe-it/security/advisories/GHSA-cg5w-9662-73vx, https://nvd.nist.gov/vuln/detail/CVE-2026-86761, https://www.vulncheck.com/advisories/snipe-it-8.6.3-before-8.7.0-authorization-bypass-via-print-endpoints, https://github.com/grokability/snipe-it/commit/7865bc56e372447631b6c0d6eb6774faf896553a
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
