CVE-2026-86761
⚪ Do wiadomości
Obejście autoryzacji w Snipe-IT pozwala na dostęp do danych użytkowników i zasobów bez odpowiednich uprawnień.
CVSS
4.3
EPSS
0.3%
Exploit
poc
Vendor
snipeitapp
Opis źródłowy (NVD)
snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to retrieve related users, assets, accessories, consumables, and components regardless of their individual model permissions.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 4.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-09-09 14:17:25 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-16 20:26:56 UTC |
Referencje
- https://github.com/grokability/snipe-it/commit/7865bc56e372447631b6c0d6eb6774faf896553a ([email protected]) [Patch]
- https://github.com/grokability/snipe-it/security/advisories/GHSA-cg5w-9662-73vx ([email protected]) [Exploit, Vendor Advisory]
- https://www.vulncheck.com/advisories/snipe-it-8.6.3-before-8.7.0-authorization-bypass-via-print-endpoints ([email protected]) [Third Party Advisory]