THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86764 (MEDIUM 6.5) — Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only assets.view on the parent asset before returning linked component details; the c

[NVD] CVE-2026-86764 (MEDIUM 6.5) — Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only assets.view on the parent asset before returning linked component details; the c

mednvdPublished 2026-09-09

CVE-2026-86764 CVSS: 6.5 MEDIUM Published: 2026-09-09T14:17:26.597

Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only assets.view on the parent asset before returning linked component details; the components.view check is applied only to the response

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86764