Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and enumerate asset tags across tenants, including soft-deleted and cross-company assets. | |
| Title | snipe-it before 8.7.0 Missing Authorization via barcode endpoint | |
| First Time appeared |
Snipeitapp
Snipeitapp snipe-it |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Snipeitapp
Snipeitapp snipe-it |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-08T15:14:05.780Z
Reserved: 2026-09-08T11:31:09.014Z
Link: CVE-2026-86737
No data.
Status : Received
Published: 2026-09-08T16:18:36.830
Modified: 2026-09-08T16:18:36.830
Link: CVE-2026-86737
No data.
OpenCVE Enrichment
Updated: 2026-09-08T17:15:17Z
-
CWE-862
Missing Authorization