Количество 3
Количество 3
CVE-2026-86759
Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail entries, compromising inventory integrity and accountability.
CVE-2026-86759
Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/hi ...
GHSA-23j2-r96m-7fq9
Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail entries, compromising inventory integrity and accountability.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-86759 Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail entries, compromising inventory integrity and accountability. | CVSS3: 7.1 | 0% Низкий | 3 дня назад | |
CVE-2026-86759 Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/hi ... | CVSS3: 7.1 | 0% Низкий | 3 дня назад | |
GHSA-23j2-r96m-7fq9 Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail entries, compromising inventory integrity and accountability. | CVSS3: 7.1 | 0% Низкий | 3 дня назад |
Уязвимостей на страницу