CVE-2026-19579
Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated, low-privileged user can supply a non-empty cancel_by_admin value to bypass the request-ownership check and cancel another user's pending checkout request. Because asset and user identifiers are sequential integers, an attacker can enumerate them to cancel every pending checkout request, disrupting the asset-request workflow. This is fixed in Snipe-IT 8.6.0.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.4
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.28%
- CWE
- CWE-639, CWE-807
- Published
- 2026-08-11
- Last modified
- 2026-08-11
Affected products
- Grokability Snipe-IT
Weakness type
Related vulnerabilities
- CVE-2026-68527 — Concrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-controlled key (cross-calendar IDOR) in the Calendar event edit dialog
- CVE-2026-88877 — Traefik v3.7.0 Authentication Bypass via from-to-www-redirect
- CVE-2026-88865 — AVideo Missing Authorization via getRestream.json.php
- CVE-2026-80354 — Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace
- CVE-2026-82582 — An authorization bypass vulnerability exists in SHIRASAGI through a user-controlled key, which may...
- CVE-2026-84062 — BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through...
- CVE-2026-87997 — Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
- CVE-2026-87994 — Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint