{"id":"CVE-2026-86761","title":"snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks","summary":"snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-639"],"vendor":"snipeitapp","product":"snipe-it","affected":["snipe-it < 8.7.0"],"patched":["snipe-it 8.7.0"],"published":"2026-09-09","updated":"2026-09-16","sourceUpdated":"2026-09-16T20:26:56.573","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86761","references":[{"url":"https://github.com/grokability/snipe-it/commit/7865bc56e372447631b6c0d6eb6774faf896553a","label":"disclosure@vulncheck.com"},{"url":"https://github.com/grokability/snipe-it/security/advisories/GHSA-cg5w-9662-73vx","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/snipe-it-8.6.3-before-8.7.0-authorization-bypass-via-print-endpoints","label":"disclosure@vulncheck.com"},{"url":"https://github.com/grokability/snipe-it/security/advisories/GHSA-cg5w-9662-73vx","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00242,"epssPercentile":0.15655,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-09T14:20:38.231057Z"},"ingestedAt":"2026-09-12T17:25:15.212Z","slug":"CVE-2026-86761","body":"## Overview\n\nsnipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to retrieve related users, assets, accessories, consumables, and components regardless of their individual model permissions.\n\n## Affected\n\n- `snipe-it < 8.7.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `snipe-it 8.7.0`","depth":"twilight","depthScore":36,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":18335,"id":"CVE-2026-86761","ts":1788966799008,"field":"exploit_available","old":"false","new":"true"}]}