CVE-2026-86774: Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy

Published Sep 9, 2026
·
Updated

Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload and delete file attachments on Asset Model records without the required models.files permission. Attackers with only assets.files permission can mutate shared model file attachments across company boundaries and bypass the dedicated models.files permission intended to restrict file management on the shared Asset Model catalog.

Affected Software

1 affected component
snipe-it<8.7.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Snipe-IT to a version that resolves this vulnerability.

    Fixed in 8.7.0
  2. Compensating control

    Until upgraded, restrict users’ ability to upload/delete file attachments on Asset Model records so that only users granted the intended models.files permission can manage attachments (because AssetModelPolicy files() cascades from assets.files in versions before 8.7.0).

Event History

Sep 9, 2026
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated user who has the assets.files permission but does not have the dedicated models.files permission can exploit it. The issue affects file attachment management on shared Asset Model records, including records across company boundaries.

2

What access does an attacker need?

The attacker needs a valid authenticated account and the assets.files permission. No user interaction is required, and exploitation can be performed over the network.

3

What can an attacker do with successful exploitation?

They can upload and delete file attachments on Asset Model records despite lacking models.files permission. This allows them to alter attachments in the shared Asset Model catalog across company boundaries.

4

Which versions are affected and what is the remediation?

Snipe-IT versions before 8.7.0 are affected. Upgrade to version 8.7.0 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203