THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-19579 (MEDIUM 5.4) — Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorizatio

[NVD] CVE-2026-19579 (MEDIUM 5.4) — Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorizatio

mednvdPublished 2026-08-11

CVE-2026-19579 CVSS: 5.4 MEDIUM Published: 2026-08-11T21:17:35.240

Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated, low-privileged user c

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19579