THREAT OPS › Threat News › [NVD] CVE-2026-19579 (MEDIUM 5.4) — Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorizatio
[NVD] CVE-2026-19579 (MEDIUM 5.4) — Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorizatio
CVE-2026-19579 CVSS: 5.4 MEDIUM Published: 2026-08-11T21:17:35.240
Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated, low-privileged user c
Indicators of compromise
- CVE-2026-19579cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19579