Junglewise Threat Intelligence

CVE-2026-86736: snipe-it checkout request counter integrity failure

CVE-2026-86736 · Severity: medium · CVSS 4.3 · Published 2026-09-08

Technologies: Snipeitapp Snipe-It. Vendors: Snipeitapp.

Executive brief

snipe-it is an asset tracking and inventory management application used by organizations to manage hardware checkouts and requests. A flaw in the checkout request handling allows authenticated users to corrupt the counter that tracks pending asset requests through duplicate submissions or repeated cancellations, causing the admin queue to show inaccurate demand and misrepresenting available inventory status.

Technical details

The vulnerability is an incorrect calculation flaw (CWE-682) in the checkout request handling logic affecting CreateCheckoutRequestAction and CancelCheckoutRequestAction components. Authenticated users can exploit two distinct attack paths: (1) calling the cancel endpoint repeatedly without an active request to drive requests_counter negative, and (2) submitting duplicate checkout requests that increment the counter multiple times while only decrementing once on cancel. The flaw stems from missing validation of active request state and stale eager-loaded data. The attack requires network access and low-privilege authentication; no user interaction is needed. Exploitation corrupts the requests_counter integrity and inflates the admin queue, misrepresenting pending demand. The patch, released in version 8.7.0, adds validation checks, fresh database queries, and transaction-level consistency between counter updates and request records.

Affected products

  • Grokability snipe-it before 8.7.0

Timeline

  • 2026-08-24: disclosed: GitHub Security Advisory published
  • 2026-08-24: patched: Fixed in version 8.7.0; commit 1f978ed068
  • 2026-09-08: advisory: CVE-2026-86736 published; NVD entry created

References

Related threats