CVE-2026-88894 | Grokability Snipe-IT up to 8.7.1 Predefined Kit Checkout Service AppServicesPredefinedKitCheckoutService user_id privileges management

SecurityVulns

A vulnerability has been found in Grokability Snipe-IT up to 8.7.1 and classified as critical. Impacted is the function AppServicesPredefinedKitCheckoutService of the component Predefined Kit Checkout Service. This manipulation of the argument user_id causes improper privilege management.

This vulnerability is registered as CVE-2026-88894. Remote exploitation of the attack is possible. No exploit is available.

The affected component should be upgraded.VulDB Recent EntriesRead More