CVE-2026-86764: Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components

Published Sep 9, 2026
·
Updated

Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only assets.view on the parent asset before returning linked component details; the components.view check is applied only to the response's availableactions.view flag and not to the returned data. As a result, an authenticated user holding only assets.view can enumerate component IDs, names, assigned quantities, and notes that are otherwise protected — the direct GET /api/v1/components/<id> endpoint correctly returns 403 Forbidden for such users.

Affected Software

1 affected component
Snipe-IT Snipe-IT<8.7.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Snipe-IT to a version that resolves this vulnerability.

    Fixed in 8.7.0
  2. Upgrade

    Upgrade Snipe-IT to a version that resolves this vulnerability.

    Fixed in 8.6.4Patch Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components

Event History

Sep 9, 2026
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which users can access the protected component information?

Any authenticated user with assets.view on a parent asset can retrieve linked component details, even if they do not have components.view. The exposed data includes component IDs, names, assigned quantities, and notes.

2

What request is used to exploit the issue?

The affected request is GET /api/v1/hardware/<asset-id>/assigned/components. Access to the parent asset is required because the endpoint checks assets.view before returning the linked component data.

3

How can administrators determine whether access controls are bypassed?

Test the assigned-components endpoint using an authenticated account that has assets.view but lacks components.view. If it returns component details while GET /api/v1/components/<id> returns 403 Forbidden for the same account, the instance is affected.

4

Which releases are affected and which release contains the fix?

Snipe-IT through 8.6.4 is affected. The issue is fixed in version 8.7.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203