snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to retrieve related users, assets, accessories, consumables, and components regardless of their individual model permissions.
References
| Link | Resource |
|---|---|
| https://github.com/grokability/snipe-it/commit/7865bc56e372447631b6c0d6eb6774faf896553a | Patch |
| https://github.com/grokability/snipe-it/security/advisories/GHSA-cg5w-9662-73vx | Exploit Vendor Advisory |
| https://www.vulncheck.com/advisories/snipe-it-8.6.3-before-8.7.0-authorization-bypass-via-print-endpoints | Third Party Advisory |
| https://github.com/grokability/snipe-it/security/advisories/GHSA-cg5w-9662-73vx | Exploit Vendor Advisory |
Configurations
History
16 Sep 2026, 20:26
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/grokability/snipe-it/commit/7865bc56e372447631b6c0d6eb6774faf896553a - Patch | |
| References | () https://github.com/grokability/snipe-it/security/advisories/GHSA-cg5w-9662-73vx - Exploit, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/snipe-it-8.6.3-before-8.7.0-authorization-bypass-via-print-endpoints - Third Party Advisory | |
| First Time |
Snipeitapp snipe-it
Snipeitapp |
|
| CPE | cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:* |
Information
Published : 2026-09-09 14:17
Updated : 2026-09-16 20:26
NVD link : CVE-2026-86761
Mitre link : CVE-2026-86761
CVE.ORG link : CVE-2026-86761
JSON object : View
Products Affected
snipeitapp
- snipe-it
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
