---
id: CVE-2026-86765
title: >-
  Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when
  assignment fields are submitted to the asset update endpoint
summary: >-
  Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when
  assignment fields are submitted to the asset update endpoint. Authenticated
  users with edit permission but explicitly denied checkout permission can
  reassign asse…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-862
vendor: snipeitapp
product: snipe-it
affected:
  - snipe-it < 8.7.0
patched:
  - snipe-it 8.7.0
published: '2026-09-09'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T20:28:04.857'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86765'
references:
  - url: >-
      https://github.com/grokability/snipe-it/commit/f71806b1e0efbd3bc2b6be61994ad2a5d5d6c206
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/grokability/snipe-it/security/advisories/GHSA-6g2g-83pc-6365
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/snipe-it-8.6.3-authorization-bypass-via-asset-update-endpoint
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/grokability/snipe-it/security/advisories/GHSA-6g2g-83pc-6365
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00405
epssPercentile: 0.31928
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T13:30:10.989732Z'
ingestedAt: '2026-09-14T15:23:07.419Z'
---

## Overview

Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset update endpoint. Authenticated users with edit permission but explicitly denied checkout permission can reassign assets, bypass check-in procedures, and alter custody records by submitting assigned_user, assigned_asset, or assigned_location parameters to PATCH /api/v1/hardware/{id}.

## Affected

- `snipe-it < 8.7.0`

## Remediation

Upgrade past the affected range:

- `snipe-it 8.7.0`
