VYPR
Vypr IntelligenceAI-generatedSep 9, 2026· 25 CVEs

Snipe-IT: 25 Authorization and Access Control Flaws Disclosed in Single Batch

Grokability's Snipe-IT faces a critical security event with 25 vulnerabilities disclosed, ranging from broken access control to data loss risks, all patched in version 8.7.0.

Key findings

  • 25 CVEs disclosed for Snipe-IT on September 9, 2026, primarily concerning authorization and access control flaws.
  • High-severity vulnerabilities allow asset reassignment, audit log tampering, and unauthorized data access.
  • Critical data loss risk in backup restore process (CVE-2026-86748) due to pre-validation database wipe.
  • Stored XSS and injection vulnerabilities present risks of script execution and external data triggering.
  • All issues addressed in Snipe-IT version 8.7.0; immediate update recommended.

On September 9, 2026, a significant batch of 25 vulnerabilities was disclosed for Snipe-IT, an open-source IT asset management system developed by Grokability. The vulnerabilities, all disclosed on the same day, span a range of severities, with several rated as High and Medium, indicating a broad impact on the security of asset management data and operations. The disclosures highlight systemic authorization and access control weaknesses within the application, affecting various modules including asset management, user permissions, and system restore functionalities.

A prominent theme across many of these vulnerabilities is broken access control and insufficient authorization checks. For instance, CVE-2026-86774 (Medium, 6.3) details a broken access control flaw in the AssetModelPolicy where authenticated users could upload or delete file attachments on Asset Model records without proper permissions. Similarly, CVE-2026-86765 (Medium, 6.5) describes how authenticated users with edit permissions but explicitly denied checkout permissions could reassign assets, bypassing check-in procedures. CVE-2026-86759 (High, 7.1) is particularly concerning, as it allows any authenticated user to reassign arbitrary assets and modify audit logs by exploiting an unprotected POST /hardware/history endpoint, potentially compromising inventory integrity and accountability.

Several vulnerabilities also touch upon cross-site scripting (XSS) and data injection risks. CVE-2026-86772 (Medium, 5.4) points to a stored XSS vulnerability in the department name rendering, where unescaped department names could allow script injection. A more critical injection vulnerability, CVE-2026-86771 (High, 7.6), involves the employee number field in the acceptance PDF generator. Versions before 8.7.0 fail to HTML-escape this field, allowing attackers with users.edit permission to inject <img> tags into the TCPDF library, potentially triggering requests to arbitrary HTTP(S) URLs.

The batch also includes vulnerabilities related to data handling and system integrity. CVE-2026-86748 (Medium, 6.1) highlights a critical data loss risk where, before validating uploaded backup archives, the restore endpoint wipes the database. This means that uploading corrupted or invalid zip files could lead to permanent data loss with no recovery path. Another vulnerability, CVE-2026-86763 (Low, 3.5), involves an authorization bypass in the Livewire importer component, where the component queried the imports table without proper checks after an initial broad ability check.

Further issues include improper scoping and filtering, such as CVE-2026-86767 (Medium, 5.0), where company scope filtering was not applied to the GET /hardware/requested endpoint when Full Multiple Company Support was enabled, allowing users to view pending asset requests from all companies. CVE-2026-86753 (Medium, 4.3) describes a failure to validate the 'requestable' flag for asset models in the POST /account/request/asset_model/{modelId} endpoint, allowing users to bypass restrictions and request non-requestable models.

The vulnerabilities were patched in Snipe-IT version 8.7.0. Users are strongly advised to update to this version to mitigate the risks associated with these numerous authorization and access control flaws. The sheer volume and interconnected nature of these vulnerabilities underscore the importance of regular security audits and timely patching for asset management systems like Snipe-IT, which often contain sensitive inventory and user data.

Key findings from this batch of disclosures include:

  • A high-severity vulnerability (CVE-2026-86759) allows any authenticated user to reassign assets and tamper with audit logs.
  • Multiple access control flaws permit unauthorized file uploads, asset reassignments, and data viewing across company scopes.
  • A critical data loss vulnerability (CVE-2026-86748) exists in the backup restore functionality.
  • Stored XSS (CVE-2026-86772) and injection vulnerabilities (CVE-2026-86771) pose risks of script execution and external data triggering.
  • All disclosed vulnerabilities were addressed in Snipe-IT version 8.7.0.

CVEs disclosed include CVE-2026-86774, CVE-2026-86773, CVE-2026-86772, CVE-2026-86771, CVE-2026-86768, CVE-2026-86767, CVE-2026-86765, CVE-2026-86764, CVE-2026-86763, CVE-2026-86761, CVE-2026-86760, CVE-2026-86759, CVE-2026-86758, CVE-2026-86757, CVE-2026-86756, CVE-2026-86755, CVE-2026-86754, CVE-2026-86753, CVE-2026-86752, CVE-2026-86749, CVE-2026-86748, CVE-2026-86747, CVE-2026-86746, CVE-2026-86745, CVE-2026-86744.

AI-written article. Grounded in 25 CVE records listed below.