CVE-2026-86757 is a high-severity vulnerability in Snipe-It, an open-source IT asset management system. The vulnerability allows authenticated users with certain permissions to read plaintext encrypted custom field values by opening asset forms, bypassing the assets.view.encrypted_custom_fields permission check. This issue affects Snipe-It versions prior to 8.7.0.
CVE-2026-86753 is a medium-severity vulnerability in Snipe-It versions before 8.7.0. Authenticated users can bypass administrative restrictions and create checkout requests for non-requestable asset models by submitting requests directly to the POST /account/request/asset_model/{modelId} endpoint. This vulnerability allows attackers to circumvent intended access controls, potentially leading to unauthoriz [truncated]
CVE-2026-86752 is a vulnerability in Snipe-It versions before 8.7.0 that allows attackers with valid sessions and assets.audit permissions to write audit log entries against cross-company assets if the query-layer scope is bypassed or refactored. This vulnerability has a medium severity and defenders should assess exposure and prioritize verification and remediation to prevent unauthorized access and data [truncated]
CVE-2026-86736 is a medium-severity vulnerability in Snipe-It before version 8.7.0 that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests, potentially leading to inaccurate representation of pending demand in the admin queue. This vulnerability affects Snipe-It installations with authenticated users who can submit chec [truncated]
CVE-2026-55516 is a HIGH severity vulnerability in Snipe-IT, an IT asset/license management system. Prior to version 8.6.2, an authorized user can manipulate a maintenance record to reference an asset outside their company scope. The vulnerability exists because the PATCH or PUT /api/v1/maintenances/{maintenance_id} endpoint checks access to the current maintenance record and asset but then fills attacker [truncated]
CVE-2026-55472 is a MEDIUM severity vulnerability in Snipe-IT, an IT asset/license management system. When Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint detects an invalid parent-child company mismatch but does not return immediately, allowing creation of a child location under a parent location from a different company. This issue is fixed in ver [truncated]