CVE-2026-86761
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Sep 09, 2026
Vendor
unknown
Description
snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location view permission can access printassigned and printallassigned endpoints to retrieve related users, assets, accessories, consumables, and components regardless of their individual model permissions.