CVE-2026-86761
בינונית 4.3
תיאור (מקור, אנגלית)
snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to retrieve related users, assets, accessories, consumables, and components regardless of their individual model permissions.
מדדים
- CVSS 3.1
-
4.3 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N - CVSS 4.0
-
5.3 (MEDIUM)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-5/10/2026
- CWE
- CWE-639
מוצרים מושפעים
snipeitapp: snipe-it
קישורים
- https://github.com/grokability/snipe-it/security/advisories/GHSA-cg5w-9662-73vx ExploitVendor Advisory
- https://github.com/grokability/snipe-it/security/advisories/GHSA-cg5w-9662-73vx ExploitVendor Advisory
- https://github.com/grokability/snipe-it/commit/7865bc56e372447631b6c0d6eb6774f… Patch
- https://www.vulncheck.com/advisories/snipe-it-8.6.3-before-8.7.0-authorization… Third Party Advisory