CVE-2026-19579: Snipe-IT Checkout Request Cancellation IDOR
Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancelbyadmin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated, low-privileged user can supply a non-empty cancelbyadmin value to bypass the request-ownership check and cancel another user's pending checkout request. Because asset and user identifiers are sequential integers, an attacker can enumerate them to cancel every pending checkout request, disrupting the asset-request workflow. This is fixed in Snipe-IT 8.6.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Snipe-IT Checkout Request Cancellation IDORto a version that resolves this vulnerability.Fixed in 8.6.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19579?
The severity of CVE-2026-19579 is medium, rated at 5.4 on the CVSS scale.
How does CVE-2026-19579 affect Snipe-IT?
CVE-2026-19579 affects Snipe-IT by allowing an authorization bypass through insecure direct object references in the checkout-request cancellation endpoint.
How do I fix CVE-2026-19579?
To fix CVE-2026-19579, upgrade Snipe-IT to version 8.6.0 or later where the vulnerability is resolved.
What type of vulnerability is CVE-2026-19579?
CVE-2026-19579 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.
Who is affected by CVE-2026-19579?
All users of Snipe-IT before version 8.6.0 are affected by CVE-2026-19579.