Junglewise Threat Intelligence

CVE-2026-86761: Snipe-IT authorization bypass in location print endpoints

CVE-2026-86761 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Snipeitapp Snipe-It. Vendors: Snipeitapp.

Executive brief

Snipe-IT is an asset management system that tracks inventory such as users, assets, and accessories across locations. Authenticated users with location view permission can access special print endpoints that bypass per-model authorization checks, allowing them to view related inventory records they should not have access to—such as users, assets, or accessories—even when their account permissions explicitly deny viewing those specific types of items.

Technical details

The vulnerability is an authorization bypass in the location print endpoints (`/locations/{id}/printassigned` and `//locations/{id}/printallassigned`) in the LocationsController. The controller performs only a location-level view authorization check (`$this->authorize('view', Location::class)`) but then returns related collections (users, assets, accessories, consumables, components) without enforcing per-model authorization guards that are present on the normal location view page. An authenticated attacker with location view permission can request these print endpoints to retrieve sensitive related records regardless of their individual model permissions. The fix, committed on 2026-07-25, adds tighter authorization constraints to the print views to match the guards applied to the standard location page. The vulnerability affects versions before 8.7.0.

Affected products

  • Snipe Snipe-IT before 8.7.0

Timeline

  • 2026-08-24: disclosed
  • 2026-07-25: patched: Fix committed; version 8.7.0 released with patch
  • 2026-09-09: advisory

References

Related threats