Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with consumables.checkout permission can perform checkouts that result in misattributed audit trail entries in the consumables_users pivot table, obscuring which operator performed the action.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 14:17
Updated : 2026-09-09 20:16
NVD link : CVE-2026-86769
Mitre link : CVE-2026-86769
CVE.ORG link : CVE-2026-86769
JSON object : View
Products Affected
No product.
CWE
CWE-282
Improper Ownership Management
