Description
snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attackers can repeatedly call cancel endpoints without active requests to drive the counter negative, or submit duplicate checkout requests to inflate the counter, misrepresenting pending demand in the admin queue.
Published: 2026-09-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Asset Request Counter Misrepresentation
Action: Patch
AI Analysis

Impact

The flaw lies in an incorrect calculation of the assets.requests_counter during checkout request processing. Authenticated users can submit duplicate checkout requests or repeatedly call the cancel endpoint when no active request exists. These actions allow the counter to be forcefully increased or driven into negative values, distorting the inventory‑management snapshot presented to administrators. The result is a credible integrity issue that can mislead resource planning and reporting operations.

Affected Systems

All installations of snipe‑it prior to version 8.7.0 are vulnerable, including any releases in the 8.x series that fall before the stated cutoff. The product, developed by grokability and identified by the CPE snipeitapp:snipe‑it, is affected for every user who can authenticate to the API or web interface.

Risk and Exploitability

The vulnerability receives a moderate CVSS score of 5.3. Its EPSS score is not available and it is not listed in the CISA KEV catalog, indicating no widespread exploitation data yet. The attack requires legitimate authentication; the exploit path is straightforward—submit duplicate checkout or cancel requests via the exposed endpoints. Even though the potential damage is limited to inventory count corruption, it can create operational disruptions or financial inaccuracies if left unmitigated.

Generated by OpenCVE AI on September 8, 2026 at 17:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade snipe‑it to version 8.7.0 or later to apply the fixed request counter logic.
  • Audit and, if possible, re‑synchronize the assets.requests_counter value against a reliable source of truth such as the database counts, and reset any incorrect entries.
  • Limit access to the checkout and cancel API endpoints by enforcing stricter role‑based permissions, reducing the risk of inadvertent counter manipulation.

Generated by OpenCVE AI on September 8, 2026 at 17:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attackers can repeatedly call cancel endpoints without active requests to drive the counter negative, or submit duplicate checkout requests to inflate the counter, misrepresenting pending demand in the admin queue.
Title snipe-it before 8.7.0 Checkout Request Counter Integrity Failure
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-682
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T14:21:56.046Z

Reserved: 2026-09-08T11:31:09.013Z

Link: CVE-2026-86736

cve-icon Vulnrichment

Updated: 2026-09-19T14:19:21.022Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T16:18:36.643

Modified: 2026-09-19T15:17:07.017

Link: CVE-2026-86736

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T17:30:05Z

Weaknesses