CVE-2026-86761

⚪ Do wiadomości

Obejście autoryzacji w Snipe-IT pozwala na dostęp do danych użytkowników i zasobów bez odpowiednich uprawnień.

CVSS
4.3
EPSS
0.3%
Exploit
poc
Vendor
snipeitapp
Opis źródłowy (NVD)

snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to retrieve related users, assets, accessories, consumables, and components regardless of their individual model permissions.

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS4.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-09-09 14:17:25 UTC
Ostatnia modyfikacja (NVD)2026-09-16 20:26:56 UTC
Referencje