Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-86769

Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column instead of the authenticated caller's id. Authenticated attackers with consumables.checkout permission can perform checkouts that result in misattributed audit trail entries in the consumables_users pivot table, obscuring which operator performed the action.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 5.4%
CVSS Severity
CVSS v3 Score 4.3


Contact Us

Shodan ® - All rights reserved