THREAT OPS › Threat News › [NVD] CVE-2026-86769 (MEDIUM 4.3) — Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with consumables.ch
[NVD] CVE-2026-86769 (MEDIUM 4.3) — Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with consumables.ch
CVE-2026-86769 CVSS: 4.3 MEDIUM Published: 2026-09-09T14:17:27.447
Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with consumables.checkout permission can perform checkouts that result
Indicators of compromise
- CVE-2026-86769cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86769