CVE-2026-86768
⚪ Do wiadomości
Błąd walidacji w Snipe-IT pozwala na tworzenie uszkodzonych referencji w inwentarzu.
CVSS
5.4
EPSS
0.2%
Exploit
poc
Vendor
snipeitapp
Opis źródłowy (NVD)
Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets. Attackers can submit POST requests to hardware, component, or consumable checkout endpoints with soft-deleted user, asset, or location IDs to create orphaned references that corrupt the asset ledger and audit trails.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.4 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-09-09 14:17:27 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-16 20:28:31 UTC |
Referencje
- https://github.com/grokability/snipe-it/security/advisories/GHSA-qffp-xpqv-gqr4 ([email protected]) [Exploit, Vendor Advisory]
- https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-improper-input-validation-via-api-checkout ([email protected]) [Third Party Advisory]