Medium severity6.5NVD Advisory· Published Sep 9, 2026· Updated Sep 9, 2026
CVE-2026-86758
CVE-2026-86758
Description
Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys. Attackers can download all license keys in bulk via CSV export or validate candidate keys through API response discrepancies without needing the viewKeys permission.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <8.7.0
- Range: <8.7.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.