PatchSiren cyber security CVE debrief
CVE-2026-86768 grokability CVE debrief
CVE-2026-86768 is a vulnerability in Snipe-IT versions prior to 8.7.0, where the API checkout endpoints fail to validate soft-deleted states. This allows authenticated users with checkout permissions to bind live inventory to trashed targets, potentially corrupting the asset ledger and audit trails. The vulnerability has a medium severity and affects Snipe-IT deployments. IT asset managers, security teams, and administrators should assess exposure and prioritize remediation. The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions.
- Vendor
- grokability
- Product
- snipe-it
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-09
- Original CVE updated
- 2026-09-16
- Advisory published
- 2026-09-09
- Advisory updated
- 2026-09-16
Who should care
IT asset managers, security teams, and administrators responsible for Snipe-IT deployments should assess exposure and prioritize remediation. This includes reviewing inventory management and access controls, verifying API usage, and upgrading to version 8.7.0 or later. Additionally, defenders should monitor for potential data inconsistencies and review compensating controls for exposed systems.
Why it matters
CVE-2026-86768 is a medium-severity vulnerability in Snipe-IT that allows authenticated users to corrupt asset ledger and audit trails. Defenders should prioritize verifying inventory management and access controls, reviewing API usage, and upgrading to version 8.7.0 or later.
- Potential data inconsistencies in asset ledger and audit trails
- Increased risk of inventory management errors
- Potential for unauthorized access to sensitive data
- Need for verification of inventory management and access controls
Technical summary
The vulnerability exists in Snipe-IT versions prior to 8.7.0, where API checkout endpoints do not validate soft-deleted states. Authenticated users with checkout permissions can bind live inventory to trashed targets, potentially corrupting the asset ledger and audit trails. The vulnerability has a CVSS score of 5.3 and is considered medium-severity. Defenders should prioritize verifying inventory management and access controls, reviewing API usage for suspicious activity, and upgrading to version 8.7.0 or later. The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions.
Defensive priority
Defenders should prioritize verifying inventory management and access controls, reviewing API usage for suspicious activity, and upgrading to version 8.7.0 or later.
Recommended defensive actions
- Verify inventory management and access controls
- Review API usage for suspicious activity
- Upgrade to version 8.7.0 or later
- Monitor for potential data inconsistencies
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. Vendor advisories and third-party reports also support the vulnerability's existence.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86768 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86768
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86768 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86768
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/grokability/snipe-it/security/advisories/GHSA-qffp-xpqv-gqr4
[email protected] - Exploit, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-improper-input-validation-via-api-checkout
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.