CVE-2026-86765 | Grokability Snipe-IT up to 8.6.x Checkout /api/v1/hardware assigned_user/assigned_asset/assigned_location improper authorization
A vulnerability has been found in Grokability Snipe-IT up to 8.6.x and classified as problematic. Impacted is an unknown function of the file /api/v1/hardware of the component Checkout. The manipulation of the argument assigned_user/assigned_asset/assigned_location leads to improper authorization.
This vulnerability is uniquely identified as CVE-2026-86765. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.VulDB Recent EntriesRead More