MEDIUM 5.3 NVD
CVE-2026-86737
snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset
snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and enumerate asset tags across tenants, including soft-deleted and cross-company assets.
Affected Products
- snipeitapp/snipe-it
References
- https://github.com/grokability/snipe-it/security/advisories/GHSA-6f4g-phw5-4g77
- https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-missing-authorization-via-barco
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-08 via NVD. Affected: snipeitapp/snipe-it.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.