Junglewise Threat Intelligence

CVE-2026-86765: Snipe-IT authorization bypass in asset update endpoint

CVE-2026-86765 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Snipeitapp Snipe-It. Vendors: Snipeitapp.

Executive brief

Snipe-IT is an asset management system used to track and control hardware deployments across organizations. A flaw allows authenticated users who can edit assets but have been explicitly denied checkout permissions to reassign assets, transfer custody, and bypass check-in workflows through the asset update API. This circumvents intended access controls and audit procedures.

Technical details

Snipe-IT implements separate permissions for asset.edit and asset.checkout operations. The vulnerability exists in the PATCH /api/v1/hardware/{id} endpoint, which accepts assignment fields (assigned_user, assigned_asset, assigned_location) but fails to enforce checkout authorization before performing the assignment. When an edit-permitted user submits an assignment field, the endpoint resolves the target and invokes the checkout method without verifying checkout permission or requiring normal checkout eligibility checks. An attacker can therefore check out unassigned assets, reassign deployed assets between custodians, bypass required check-in transitions, and create fraudulent audit records—all while being denied direct checkout permission. The fix is available in version 8.7.0.

Affected products

  • Snipe Snipe-IT before 8.7.0

Timeline

  • 2026-08-24: disclosed
  • 2026-07-25: patched: Fix committed; version 8.7.0 released

References

Related threats