Medium severity4.3NVD Advisory· Published Sep 9, 2026· Updated Sep 9, 2026
CVE-2026-86753
CVE-2026-86753
Description
snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint. Authenticated users can bypass administrative restrictions and create checkout requests for non-requestable asset models by submitting requests directly to the endpoint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <8.7.0
- Range: <8.7.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.