CVE-2026-86773: Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints

Published Sep 9, 2026
·
Updated

Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updateAccessory, and updateModel endpoints and in the storeModel endpoint for Predefined Kits. The existing check authorizes only the parent Predefined Kit (update on PredefinedKit) and not the child object being attached. As a result, an authenticated user holding only the kits.edit permission can attach a License, Consumable, Accessory, or Asset Model that they are otherwise denied (HTTP 403) from reading directly to a Predefined Kit, and the kit relation index then discloses the attached object's name back to that low-privilege user. This is the update-path and storeModel counterpart to CVE-2026-55478, which fixed only the storeLicense, storeConsumable, and storeAccessory methods in 8.6.2. Note that updateModel was code-vulnerable in 8.6.3 but not reachable in practice because a route-name typo bound the route to a nonexistent controller method, causing HTTP 500 responses. The issue is fixed in Snipe-IT 8.7.0.

Affected Software

1 affected component
Snipe-IT Snipe-IT<=8.6.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Snipe-IT to a version that resolves this vulnerability.

    Fixed in 8.7.0
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch CVE-2026-55478

Event History

Sep 9, 2026
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which users can exploit this issue?

An authenticated user with the kits.edit permission can exploit it, even if they are denied direct read access to the License, Consumable, Accessory, or Asset Model being attached.

2

What information can the affected user obtain?

After attaching an otherwise inaccessible child object to a Predefined Kit, the user can view that object's name through the kit relation index. The stated impact is limited to low confidentiality and integrity impact, with no availability impact.

3

Are all of the identified endpoint paths practically exploitable in version 8.6.3?

The updateLicense, updateConsumable, updateAccessory, and storeModel paths are affected. Although updateModel was vulnerable in code, it was not reachable in practice in 8.6.3 because a route-name typo caused HTTP 500 responses.

4

What version resolves the issue?

The issue is fixed in Snipe-IT 8.7.0. The earlier 8.6.2 fix addressed only the storeLicense, storeConsumable, and storeAccessory methods, not the update-path and storeModel issues described here.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203