Description
snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint. Authenticated users can bypass administrative restrictions and create checkout requests for non-requestable asset models by submitting requests directly to the endpoint.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Asset Checkout
Action: Apply Patch
AI Analysis

Impact

Snipe‑IT versions prior to 8.7.0 do not validate the requestable flag when processing POST requests to /account/request/asset_model/{modelId}. This allows an authenticated user to submit a checkout request for an asset model that has been marked as non-requestable, effectively bypassing the intended administrative restriction. The consequence is that assets can be removed from inventory without proper approval, which may lead to loss of asset control, billing inaccuracies, or unauthorized asset access.

Affected Systems

The affected software is Snipe‑IT produced by grokability. All releases before version 8.7.0 are vulnerable. No additional version qualifiers are provided.

Risk and Exploitability

The CVSS base score for this issue is 5.3, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires authenticated access to the system; a legitimate user account can target the endpoint directly. Once the bypass is achieved, the attacker can generate checkout requests for non-requestable assets and thereby compromise inventory integrity. Because only authenticated actors can exploit the flaw, the risk is contingent on internal threat models and the safeguarding of user credentials.

Generated by OpenCVE AI on September 9, 2026 at 15:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to 8.7.0 or later, which implements validation of the requestable flag on the asset_model endpoint.
  • Restrict the ability to create checkout requests to users with explicit permission, removing the ability for general users to invoke the endpoint directly.
  • Verify and audit all asset models to ensure the requestable flag is set correctly according to organizational policy and correct any misconfigurations.

Generated by OpenCVE AI on September 9, 2026 at 15:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint. Authenticated users can bypass administrative restrictions and create checkout requests for non-requestable asset models by submitting requests directly to the endpoint.
Title snipe-it before 8.7.0 Business Logic Bypass via asset_model endpoint
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-863
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-09T14:27:58.495Z

Reserved: 2026-09-08T11:32:11.096Z

Link: CVE-2026-86753

cve-icon Vulnrichment

Updated: 2026-09-09T14:27:53.515Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:24.447

Modified: 2026-09-14T20:20:32.003

Link: CVE-2026-86753

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T17:15:06Z

Weaknesses