{"id":"CVE-2026-86744","title":"Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) contain a race condition in the asset checkout paths","summary":"Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) contain a race condition in the asset checkout paths. Api\\AssetsController::checkout() and Assets\\AssetCheckoutController::store() call Asset::availableForChec…","severity":"low","cvss":2.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-362"],"vendor":"snipeitapp","product":"snipe-it","affected":["snipe-it < 8.7.0"],"patched":["snipe-it 8.7.0"],"published":"2026-09-09","updated":"2026-09-18","sourceUpdated":"2026-09-18T18:17:19.880","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86744","references":[{"url":"https://github.com/grokability/snipe-it/commit/f71806b1e0efbd3bc2b6be61994ad2a5d5d6c206","label":"disclosure@vulncheck.com"},{"url":"https://github.com/grokability/snipe-it/security/advisories/GHSA-h992-9438-26v8","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-race-condition-in-asset-checkout","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"epss":0.00212,"epssPercentile":0.11778,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-18T17:09:37.025208Z"},"ingestedAt":"2026-09-14T00:18:59.482Z","slug":"CVE-2026-86744","body":"## Overview\n\nSnipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) contain a race condition in the asset checkout paths. Api\\AssetsController::checkout() and Assets\\AssetCheckoutController::store() call Asset::availableForCheckout() outside the mutation path and then invoke Asset::checkOut() without taking a row lock or re-checking availability, so two concurrent checkout requests for the same available asset can both observe it as available and both commit. This produces duplicate checkout-history rows, a doubled checkout_counter, and two CheckoutableCheckedOut events for a single-assignment asset, corrupting the audit trail and utilization/reconciliation reporting; the asset's final assigned_to remains singular, so the visible assignment stays intact. Exploitation requires an authenticated session holding the assets.checkout permission (or superuser) and precise concurrent timing. Fixed in 8.7.0.\n\n## Affected\n\n- `snipe-it < 8.7.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `snipe-it 8.7.0`","depth":"sunlit","depthScore":12,"depthScoreParts":{"impact":12.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}