MEDIUMVulnerability

CVE-2026-86758

Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys. Attackers can download all license keys in bulk via CSV export or validate candidate keys through API response discrepancies without needing the viewKeys permission.

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-86758
signal_observed_at
2026-09-17T21:32:24+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
published_at
2026-09-09T14:17:25.430
last_modified
2026-09-16T20:26:12.513

Related Entities (3)

AFFECTS_PRODUCT (1)

[Product]

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Observable Response Discrepancy

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86758 — Ninja Signal Threat Intelligence | Ninja Signal