CVE-2026-86759

🟡 Monitoruj

Brak autoryzacji w Snipe-IT pozwala uwierzytelnionym użytkownikom na modyfikację zasobów i logów audytowych.

CVSS
7.1
EPSS
0.2%
Exploit
poc
Vendor
snipeitapp
Opis źródłowy (NVD)

Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail entries, compromising inventory integrity and accountability.

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-09-09 14:17:25 UTC
Ostatnia modyfikacja (NVD)2026-09-16 20:26:27 UTC
Referencje