THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86736 (MEDIUM 4.3) — snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attackers can repeatedly call cancel

[NVD] CVE-2026-86736 (MEDIUM 4.3) — snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attackers can repeatedly call cancel

mednvdPublished 2026-09-08

CVE-2026-86736 CVSS: 4.3 MEDIUM Published: 2026-09-08T16:18:36.643

snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attackers can repeatedly call cancel endpoints without active requests to drive the count

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86736