CVE-2026-86769

Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with consumables.checkout permission can perform checkouts that result in misattributed audit trail entries in the consumables_users pivot table, obscuring which operator performed the action.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 14:17

Updated : 2026-09-09 20:16


NVD link : CVE-2026-86769

Mitre link : CVE-2026-86769

CVE.ORG link : CVE-2026-86769


JSON object : View

Products Affected

No product.

CWE
CWE-282

Improper Ownership Management