CVE-2026-86769

⚪ Do wiadomości

Błąd zarządzania własnością w Snipe-IT pozwala na fałszowanie historii operacji przez atakujących.

CVSS
4.3
EPSS
0.2%
Exploit
poc
Vendor
snipeitapp
Opis źródłowy (NVD)

Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with consumables.checkout permission can perform checkouts that result in misattributed audit trail entries in the consumables_users pivot table, obscuring which operator performed the action.

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS4.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-09-09 14:17:27 UTC
Ostatnia modyfikacja (NVD)2026-09-16 20:28:38 UTC
Referencje