Junglewise Threat Intelligence

CVE-2026-86764: Snipe-IT permission bypass in assigned components endpoint

CVE-2026-86764 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Snipeitapp Snipe-It. Vendors: Snipeitapp.

Executive brief

Snipe-IT is an open-source asset management system used to track hardware inventory and components across organizations. A permissions flaw in version 8.6.4 and earlier allows authenticated users with limited asset-viewing permissions to view sensitive component information (IDs, names, quantities, and notes) they should not be able to access, effectively allowing unauthorized information disclosure.

Technical details

The vulnerability is a missing authorization (CWE-862) in the GET /api/v1/hardware/<asset-id>/assigned/components endpoint. The endpoint checks only the assets.view permission on the parent asset before returning linked component details, but fails to enforce the required components.view permission on the actual component data returned. The components.view check exists in the codebase but is only applied to the response's available_actions.view flag (UI rendering), not to data disclosure. An authenticated attacker with assets.view permission can enumerate component IDs, names, assigned quantities, and notes by querying this endpoint, while the direct GET /api/v1/components/<id> endpoint correctly returns 403 Forbidden without components.view permission. The flaw was fixed in version 8.7.0.

Affected products

  • Grokability Snipe-IT through 8.6.4

Timeline

  • 2026-09-09: disclosed
  • 2026-08-24: patched: patch released in version 8.7.0

References

Related threats