THREAT OPS › Threat News › [NVD] CVE-2026-86754 (HIGH 7.3) — Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated user to register OAuth clients with attacker-controlled redirect URIs. Attackers can trick administrators into approving consent screens, then exchange autho
[NVD] CVE-2026-86754 (HIGH 7.3) — Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated user to register OAuth clients with attacker-controlled redirect URIs. Attackers can trick administrators into approving consent screens, then exchange autho
CVE-2026-86754 CVSS: 7.3 HIGH Published: 2026-09-09T14:17:24.590
Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated user to register OAuth clients with attacker-controlled redirect URIs. Attackers can trick administrators into approving consent screens, then exchange authorization codes for bearer tokens inheriting full admin
Indicators of compromise
- CVE-2026-86754cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86754