CVE-2026-86765 | Grokability Snipe-IT up to 8.6.x Checkout /api/v1/hardware assigned_user/assigned_asset/assigned_location improper authorization

SecurityVulns

A vulnerability has been found in Grokability Snipe-IT up to 8.6.x and classified as problematic. Impacted is an unknown function of the file /api/v1/hardware of the component Checkout. The manipulation of the argument assigned_user/assigned_asset/assigned_location leads to improper authorization.

This vulnerability is uniquely identified as CVE-2026-86765. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded.VulDB Recent EntriesRead More