CVE-2026-86768

⚪ Do wiadomości

Błąd walidacji w Snipe-IT pozwala na tworzenie uszkodzonych referencji w inwentarzu.

CVSS
5.4
EPSS
0.2%
Exploit
poc
Vendor
snipeitapp
Opis źródłowy (NVD)

Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets. Attackers can submit POST requests to hardware, component, or consumable checkout endpoints with soft-deleted user, asset, or location IDs to create orphaned references that corrupt the asset ledger and audit trails.

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.4
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-09-09 14:17:27 UTC
Ostatnia modyfikacja (NVD)2026-09-16 20:28:31 UTC
Referencje