CVE-2026-86758: Snipe-IT before 8.7.0 License Key Exposure via CSV Export
Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys. Attackers can download all license keys in bulk via CSV export or validate candidate keys through API response discrepancies without needing the viewKeys permission.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated Snipe-IT user with the licenses.view permission can exploit it. The user does not need the separate viewKeys permission.
What access can an attacker obtain?
An affected user can download license keys in bulk through CSV export. They can also use API index endpoint response differences to validate candidate product keys.
Which deployments are affected?
Snipe-IT versions before 8.7.0 are affected. Deployments where users have licenses.view permission should be considered exposed, even if those users are not intended to view license keys.