Description
Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updateAccessory, and updateModel endpoints and in the storeModel endpoint for Predefined Kits. The existing check authorizes only the parent Predefined Kit (update on PredefinedKit) and not the child object being attached. As a result, an authenticated user holding only the kits.edit permission can attach a License, Consumable, Accessory, or Asset Model that they are otherwise denied (HTTP 403) from reading directly to a Predefined Kit, and the kit relation index then discloses the attached object's name back to that low-privilege user. This is the update-path and storeModel counterpart to CVE-2026-55478, which fixed only the storeLicense, storeConsumable, and storeAccessory methods in 8.6.2. Note that updateModel was code-vulnerable in 8.6.3 but not reachable in practice because a route-name typo bound the route to a nonexistent controller method, causing HTTP 500 responses. The issue is fixed in Snipe-IT 8.7.0.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized object association with kits
Action: Apply Patch
AI Analysis

Impact

Snipe‑IT versions below 8.7.0 allow an authenticated user who has only the kits.edit permission to attach a License, Consumable, Accessory, or Asset Model to a Predefined Kit through the updateLicense, updateConsumable, updateAccessory, updateModel, or storeModel endpoints. The application performs authorization only on the parent kit, not on the child object; consequently, the attachment succeeds even though the user would normally receive a 403 error when trying to read the object directly. After attachment, the kit relation index endpoint reveals the name of the attached object, providing a covert channel of disclosure. The vulnerability is an instance of object‑level authorization failure (CWE-863).

Affected Systems

Customers running Snipe‑IT version 8.6.3 or earlier are affected. The issue is fixed from version 8.7.0 onwards.

Risk and Exploitability

The CVSS score is 5.3, a medium severity that permits privilege escalation within a trusted realm of users. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attacking this flaw requires an authenticated session with kits.edit permission; an attacker could over‑attach privileged objects and gain indirect access to confidential names via the kit index.

Generated by OpenCVE AI on September 9, 2026 at 15:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to version 8.7.0 or newer.
  • Restrict the kits.edit role to administrators or tightly controlled personnel.
  • Review and minimise kit‑association endpoints, ensuring that kit indices do not expose child object names to users lacking broader read permissions.

Generated by OpenCVE AI on September 9, 2026 at 15:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updateAccessory, and updateModel endpoints and in the storeModel endpoint for Predefined Kits. The existing check authorizes only the parent Predefined Kit (update on PredefinedKit) and not the child object being attached. As a result, an authenticated user holding only the kits.edit permission can attach a License, Consumable, Accessory, or Asset Model that they are otherwise denied (HTTP 403) from reading directly to a Predefined Kit, and the kit relation index then discloses the attached object's name back to that low-privilege user. This is the update-path and storeModel counterpart to CVE-2026-55478, which fixed only the storeLicense, storeConsumable, and storeAccessory methods in 8.6.2. Note that updateModel was code-vulnerable in 8.6.3 but not reachable in practice because a route-name typo bound the route to a nonexistent controller method, causing HTTP 500 responses. The issue is fixed in Snipe-IT 8.7.0.
Title Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-863
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-09T14:32:43.294Z

Reserved: 2026-09-08T11:35:02.617Z

Link: CVE-2026-86773

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:28.040

Modified: 2026-09-16T20:23:42.817

Link: CVE-2026-86773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:30:06Z

Weaknesses