Medium severity4.3NVD Advisory· Published Sep 9, 2026· Updated Sep 9, 2026
CVE-2026-86761
CVE-2026-86761
Description
snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to retrieve related users, assets, accessories, consumables, and components regardless of their individual model permissions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <8.7.0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.