---
id: CVE-2026-86744
title: >-
  Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix)
  contain a race condition in the asset checkout paths
summary: >-
  Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix)
  contain a race condition in the asset checkout paths.
  Api\AssetsController::checkout() and Assets\AssetCheckoutController::store()
  call Asset::availableForChec…
severity: low
cvss: 2.2
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-362
vendor: snipeitapp
product: snipe-it
affected:
  - snipe-it < 8.7.0
patched:
  - snipe-it 8.7.0
published: '2026-09-09'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:19.880'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86744'
references:
  - url: >-
      https://github.com/grokability/snipe-it/commit/f71806b1e0efbd3bc2b6be61994ad2a5d5d6c206
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/grokability/snipe-it/security/advisories/GHSA-h992-9438-26v8
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-race-condition-in-asset-checkout
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00271
epssPercentile: 0.17204
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T17:09:37.025208Z'
ingestedAt: '2026-09-14T00:18:59.482Z'
---

## Overview

Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) contain a race condition in the asset checkout paths. Api\AssetsController::checkout() and Assets\AssetCheckoutController::store() call Asset::availableForCheckout() outside the mutation path and then invoke Asset::checkOut() without taking a row lock or re-checking availability, so two concurrent checkout requests for the same available asset can both observe it as available and both commit. This produces duplicate checkout-history rows, a doubled checkout_counter, and two CheckoutableCheckedOut events for a single-assignment asset, corrupting the audit trail and utilization/reconciliation reporting; the asset's final assigned_to remains singular, so the visible assignment stays intact. Exploitation requires an authenticated session holding the assets.checkout permission (or superuser) and precise concurrent timing. Fixed in 8.7.0.

## Affected

- `snipe-it < 8.7.0`

## Remediation

Upgrade past the affected range:

- `snipe-it 8.7.0`
