SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-86752

MEDIUM · CVSS 5.4 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Snipe-IT versions prior to 8.7.0 are vulnerable due to inadequate enforcement of per-instance FMCS scoping in asset audit endpoints, allowing attackers with valid sessions and permissions to manipulate audit log entries for assets across different companies. This flaw could lead to unauthorized access and potential data integrity issues. Organizations using affected versions should prioritize patching to mitigate risks associated with unauthorized asset auditing.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86752
Severity
MEDIUM
CVSS
5.4
EPSS
0.19%

Original NVD Description

snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and assets.audit permissions could write audit log entries against cross-company assets if the query-layer scope were bypassed or refactored.

Related CVEs

Other vulnerabilities affecting the same vendor(s)