Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-19579

Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated, low-privileged user can supply a non-empty cancel_by_admin value to bypass the request-ownership check and cancel another user's pending checkout request. Because asset and user identifiers are sequential integers, an attacker can enumerate them to cancel every pending checkout request, disrupting the asset-request workflow. This is fixed in Snipe-IT 8.6.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 15.0%
CVSS Severity
CVSS v3 Score 5.4


Contact Us

Shodan ® - All rights reserved