Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-86759

Опубликовано: 09 сент. 2026
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail entries, compromising inventory integrity and accountability.

EPSS

Процентиль: 10%
0.00202
Низкий

7.1 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.1
debian
3 дня назад

Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/hi ...

CVSS3: 7.1
github
3 дня назад

Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail entries, compromising inventory integrity and accountability.

EPSS

Процентиль: 10%
0.00202
Низкий

7.1 High

CVSS3

Дефекты

CWE-862