VYPR
Vypr IntelligenceAI-generatedSep 10, 2026· 16 CVEs

Snipe-IT: 16 Authorization and Access Control Flaws Disclosed in Single Batch

A batch of 16 vulnerabilities, primarily authorization and access control flaws, were disclosed for Snipe-IT, with fixes available in version 8.7.0.

Key findings

  • 16 authorization and access control vulnerabilities disclosed for Snipe-IT in a single batch.
  • High-severity flaws allow unauthorized data access, asset reassignment, and file reads.
  • SAML authentication bypass and XSS vulnerabilities pose significant security risks.
  • All issues addressed in Snipe-IT version 8.7.0; immediate update recommended.
  • Vulnerabilities span API endpoints, authentication, PDF generation, and file handling.

On September 9, 2026, a significant batch of 16 vulnerabilities was disclosed for Snipe-IT, an open-source IT asset management system. The vulnerabilities, disclosed between September 8 and September 10, 2026, primarily concern authorization and access control flaws, with several high-severity issues allowing for unauthorized data access and manipulation. All identified issues have been addressed in Snipe-IT version 8.7.0, and users are strongly recommended to update immediately.

Several vulnerabilities revolve around improper authorization checks in various API endpoints and core functionalities. CVE-2026-86750, a high-severity flaw, allows authenticated users to persist user records with unauthorized company IDs via the REST API before company assignment is validated. Similarly, CVE-2026-86765, another medium-severity issue, permits authenticated users with edit permissions but denied checkout permissions to reassign assets and bypass check-in procedures by submitting assigned user fields to the asset update endpoint. The consumables checkout API endpoint is also affected by improper ownership management (CVE-2026-86769), where authenticated attackers can perform checkouts as other users. Furthermore, CVE-2026-86764 highlights a lack of component view permission enforcement on an API endpoint, potentially exposing linked component details.

Other critical flaws include injection vulnerabilities and cross-site scripting (XSS). CVE-2026-86751, a high-severity vulnerability, allows authenticated users to read arbitrary server files and issue server-side HTTP requests by exploiting improperly sanitized markdown image syntax in note fields. CVE-2026-86771, also high-severity, involves a failure to HTML-escape the employee number field in the acceptance PDF generator, enabling attackers with edit permissions to inject malicious content into TCPDF's writeHTML() function. A stored XSS vulnerability exists in CVE-2026-86772, where department names are rendered unescaped, allowing users with edit permissions to inject malicious scripts.

Authentication mechanisms were also targeted. CVE-2026-86770, a high-severity vulnerability, exploits a failure to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by leveraging accent or case variants of usernames due to default database collation. Additionally, CVE-2026-86762 indicates that deactivating a user does not revoke their Passport personal access tokens, allowing deactivated accounts to maintain API access. An open redirect vulnerability in CVE-2026-86756 within the SAML assertion-consumer endpoint could be exploited for phishing attacks.

The batch also includes vulnerabilities related to data integrity and export functionalities. CVE-2026-86766 describes a race condition in the consumable checkout API that could lead to incorrect quantity validation. CVE-2026-86745 points to a flaw in a location-scoping report CSV export that streams data without proper sanitization. CVE-2026-86742 highlights that formula elements are not neutralized in an "unaccepted assets" acceptance report CSV export, potentially leading to data corruption. CVE-2026-86736 involves an incorrect calculation in checkout request handling, allowing authenticated users to corrupt the assets.requests_counter. Finally, CVE-2026-86749 details a silently failed storage write operation in the image upload process that could lead to the deletion of previous images without a successful replacement.

The comprehensive fix for all these vulnerabilities is available in Snipe-IT version 8.7.0. Users are urged to apply this update to mitigate risks associated with unauthorized access, data manipulation, and potential code execution. The disclosure of this large batch underscores the importance of timely patching for IT asset management systems, which often contain sensitive information about an organization's hardware and software assets.

Vypr Intelligence reported on this batch, noting that the vulnerabilities primarily concerned authorization and access control. They highlighted the risks of asset reassignment, audit log tampering, and unauthorized data access, emphasizing the critical need for immediate updates.

The vulnerabilities disclosed include:

  • CVE-2026-88894: Predefined kit checkout path bypasses FMCS tenant isolation.
  • CVE-2026-86772: Stored XSS in department names due to unescaped rendering.
  • CVE-2026-86771: Injection vulnerability in acceptance PDF generator via employee number field.
  • CVE-2026-86770: SAML authentication bypass via case-insensitive username validation.
  • CVE-2026-86769: Improper ownership management in consumables checkout API.
  • CVE-2026-86766: Race condition in consumable checkout API.
  • CVE-2026-86765: Checkout authorization bypass on asset update endpoint.
  • CVE-2026-86764: Missing components.view permission enforcement on API endpoint.
  • CVE-2026-86762: Deactivated users retain API access via Passport tokens.
  • CVE-2026-86756: Open redirect vulnerability in SAML assertion-consumer endpoint.
  • CVE-2026-86751: Arbitrary file read and SSRF via markdown image syntax in notes.
  • CVE-2026-86750: Company assignment validation bypass in user record persistence via API.
  • CVE-2026-86749: Silent failure in storage write operations during image uploads.
  • CVE-2026-86745: Unsanitized data in location-scoping report CSV export.
  • CVE-2026-86742: Formula elements not neutralized in "unaccepted assets" CSV export.
  • CVE-2026-86736: Incorrect calculation in checkout request handling corrupts requests_counter.

All these issues were fixed in Snipe-IT version 8.7.0.

AI-written article. Grounded in 16 CVE records listed below.