CVE-2026-86774

Source
https://cve.org/CVERecord?id=CVE-2026-86774
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86774.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-86774
Aliases
  • GHSA-rhrf-7x22-x2rj
Published
2026-09-09T13:32:30Z
Modified
2026-09-10T03:48:29Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy
Details

Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload and delete file attachments on Asset Model records without the required models.files permission. Attackers with only assets.files permission can mutate shared model file attachments across company boundaries and bypass the dedicated models.files permission intended to restrict file management on the shared Asset Model catalog.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-284"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86774.json"
}
References

Affected packages

Git / github.com/grokability/snipe-it

Affected ranges

Type
GIT
Repo
https://github.com/grokability/snipe-it
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "8.6.3"
        },
        {
            "fixed": "8.7.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86774.json"