CVE-2026-86758
CVE-2026-86758 is a medium-severity vulnerability in Snipeitapp Snipe-it with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-204.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- CVSS v4: 7.1
- EPSS exploit prediction: 0% (33rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-204
- Affected product: Snipeitapp Snipe-it
- Published:
- Last modified:
Description
Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys. Attackers can download all license keys in bulk via CSV export or validate candidate keys through API response discrepancies without needing the viewKeys permission.
Frequently asked questions
- What is CVE-2026-86758?
- Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys. Attackers can download all license keys in bulk via CSV export or validate candidate keys through API response discrepancies without needing the viewKeys permission.
- How severe is CVE-2026-86758?
- CVE-2026-86758 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2026-86758 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (33rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-86758?
- CVE-2026-86758 affects Snipeitapp Snipe-it. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-86758?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-86758 published?
- CVE-2026-86758 was published on 2026-09-09 and last updated on 2026-09-16.
References
- https://github.com/grokability/snipe-it/security/advisories/GHSA-5jcj-c9p3-82q7
- https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-license-key-exposure-via-csv-export
Affected products (1)
- cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
More vulnerabilities in Snipeitapp Snipe-it
- CVE-2025-63601 — Critical (CVSS 9.9): Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to…
- CVE-2026-37709 — Critical (CVSS 9.8): Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit…
- CVE-2026-85617 — High (CVSS 8.8): snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that…
- CVE-2026-55643 — High (CVSS 8.8): Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can…
- CVE-2026-55483 — High (CVSS 8.8): Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission…
- CVE-2026-44832 — High (CVSS 8.8): Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit…
All CVEs affecting Snipeitapp Snipe-it →
Other CWE-204 vulnerabilities
- CVE-2018-25350 — Critical (CVSS 9.8): userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid…
- CVE-2026-15747 — Critical (CVSS 9.1): Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a…
- CVE-2026-69519 — High (CVSS 8.6): Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a…
- CVE-2025-5485 — High (CVSS 8.6): User names used to access the web management interface are limited to the device identifier, which is a numerical…
- CVE-2026-19205 — High (CVSS 7.5): Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting. This…
- CVE-2026-19080 — High (CVSS 7.5): Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account…