Description
Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with consumables.checkout permission can perform checkouts that result in misattributed audit trail entries in the consumables_users pivot table, obscuring which operator performed the action.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Misattribution of audit log entries
Action: Patch
AI Analysis

Impact

Snipe-IT versions before 8.7.0 record the ID of the target user in the checkout action instead of the ID of the authenticated caller. This improper ownership management causes all audit trail entries in the consumables_users table to be associated with the wrong user. The result is a loss of traceability for actions performed on consumables, which can enable malicious insiders or attackers to conceal their activity and undermine accountability mechanisms.

Affected Systems

The vulnerability applies to the Snipe-IT asset management application provided by grokability. All releases prior to version 8.7.0 are affected; no specific patch releases other than 8.7.0 or later are available. Any instance running an earlier version is susceptible if the consumables.checkout API is available.

Risk and Exploitability

The risk level is assessed as medium with a CVSS score of 5.3. Exploitation requires that the attacker be an authenticated user with the consumables.checkout permission, so remote unauthenticated attacks are not possible. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that while the likelihood of exploitation is uncertain, the potential impact on accountability could be significant. The primary attack path is a normal API call to the consumables checkout endpoint where the payload includes the user ID to be checked out.

Generated by OpenCVE AI on September 9, 2026 at 15:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe-IT to version 8.7.0 or later to replace the vulnerable checkout logic
  • Restrict or revoke the consumables.checkout permission from users until the application is updated
  • Audit existing consumables_users records for misattributed entries and correct ownership where possible

Generated by OpenCVE AI on September 9, 2026 at 15:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with consumables.checkout permission can perform checkouts that result in misattributed audit trail entries in the consumables_users pivot table, obscuring which operator performed the action.
Title Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-282
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-20T00:35:32.500Z

Reserved: 2026-09-08T11:35:02.617Z

Link: CVE-2026-86769

cve-icon Vulnrichment

Updated: 2026-09-20T00:31:08.592Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:27.447

Modified: 2026-09-20T01:16:31.160

Link: CVE-2026-86769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T18:30:09Z

Weaknesses
  • CWE-282

    Improper Ownership Management