CVE-2026-86746

Snipe-IT before 8.7.0 contains an authorization bypass vulnerability in Livewire components that enforce authorization only at the route level, not within component lifecycle methods. Attackers with a valid authenticated session can replay signed component snapshots via POST /livewire/update to invoke protected methods and escalate privileges, including creating OAuth clients, minting personal access tokens, and accessing sensitive admin data.

Scoring

Severity
HIGH
CVSS base score
7.4
CVSS vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWE
CWE-269
Published
2026-09-09
Last modified
2026-09-09

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs