Description
Snipe-IT versions up to and including 8.6.3 contain a race condition (TOCTOU) in the consumable checkout API endpoint (POST /api/v1/consumables/{consumable_id}/checkout). The requested quantity is validated against the number of remaining units before the database transaction begins, and the transaction then creates the checkout records without locking the consumable row or re-checking availability. An authenticated user with permission to check out consumables can submit concurrent checkout requests for the same consumable so that both requests pass the availability check and succeed, over-allocating stock and driving the remaining inventory negative (e.g., a consumable with 1 remaining unit ends at -1 after two concurrent 1-unit checkouts). The issue is fixed in 8.7.0, which re-fetches the parent row under lockForUpdate inside the transaction and re-validates availability.
Published: 2026-09-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Race Condition leading to inventory over–allocation and negative stock
Action: Patch
AI Analysis

Impact

Snipe-IT versions up to 8.6.3 contain a time‑of‑check to time‑of‑use flaw in the consumable checkout API. An authenticated user can send multiple concurrent checkout requests that all validate the available quantity before a database transaction locks the record. The transaction then creates checkout entries without re‑checking stock, allowing the remaining quantity to become negative. This flaw does not execute arbitrary code but corrupts inventory data, potentially causing financial loss or operational outages.

Affected Systems

All installations of Snipe‑IT v8.6.3 and earlier are vulnerable. The flaw applies to the consumable checkout endpoint POST /api/v1/consumables/{consumable_id}/checkout. The affected product is the Snipe‑IT asset tracking system maintained by grokability. Fixed in version 8.7.0 and later, which re‑locks the consumable row and re‑validates availability inside the transaction.

Risk and Exploitability

The severity score is 7.1, indicating a moderate to high risk. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation yet. Exploitation requires an authenticated user with permission to check out consumables. By submitting two or more concurrent requests for the same item, an attacker can force the stock count negative, creating obvious inventory discrepancies that may be hard to detect without audit processes. The attack path is straightforward and does not require specialized skills beyond sending rapid parallel HTTP requests.

Generated by OpenCVE AI on September 9, 2026 at 15:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to version 8.7.0 or later to activate the transaction lock and re‑validation fix.
  • Restrict or serialize concurrent consumable checkout operations during the upgrade window to prevent inventory inconsistency.
  • After the upgrade, audit inventory records for negative quantities and reconcile any discrepancies.
  • Optional: Temporarily revoke or reduce checkout permissions for users until the system is elevated and locked.

Generated by OpenCVE AI on September 9, 2026 at 15:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT versions up to and including 8.6.3 contain a race condition (TOCTOU) in the consumable checkout API endpoint (POST /api/v1/consumables/{consumable_id}/checkout). The requested quantity is validated against the number of remaining units before the database transaction begins, and the transaction then creates the checkout records without locking the consumable row or re-checking availability. An authenticated user with permission to check out consumables can submit concurrent checkout requests for the same consumable so that both requests pass the availability check and succeed, over-allocating stock and driving the remaining inventory negative (e.g., a consumable with 1 remaining unit ends at -1 after two concurrent 1-unit checkouts). The issue is fixed in 8.7.0, which re-fetches the parent row under lockForUpdate inside the transaction and re-validates availability.
Title Snipe-IT 8.6.3 Race Condition via Consumable Checkout
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-362
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-09T14:18:02.631Z

Reserved: 2026-09-08T11:33:02.642Z

Link: CVE-2026-86766

cve-icon Vulnrichment

Updated: 2026-09-09T14:17:39.313Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:26.963

Modified: 2026-09-16T20:28:15.870

Link: CVE-2026-86766

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:30:06Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')