CVE-2026-86761: Snipeitapp Snipe-It
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to retrieve related users, assets, accessories, consumables, and components regardless of their individual model permissions.
Affected products
- Snipeitapp Snipe-It: before 8.7.0 (fixed in 8.7.0)
Published 2026-09-09. Last modified 2026-09-16.