CVE-2026-19579
Last modified
CVE-2026-19579 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated, low-privileged user can supply a non-empty cancel_by_admin value to bypass the request-ownership check and cancel another user's pending checkout request. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated, low-privileged user can supply a non-empty cancel_by_admin value to bypass the request-ownership check and cancel another user's pending checkout request. Because asset and user identifiers are sequential integers, an attacker can enumerate them to cancel every pending checkout request, disrupting the asset-request workflow. This is fixed in Snipe-IT 8.6.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Snipeitapp | Snipe-It | < 8.6.0 |
References
- https://www.tenable.com/security/research/tra-2026-54Third Party Advisory, Exploit
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-19579?
How severe is CVE-2026-19579?
How do I fix CVE-2026-19579?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-19562Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-19563Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-19565Apache::AppSamurai::Util versions through 1.01 for Perl gene…3.7
- CVE-2026-19566Net::CIDR::Set versions before 0.23 for Perl allow memory ex…7.5
- CVE-2026-19568A maliciously crafted SVG file, when parsed through Autodesk…7.8
- CVE-2026-19573The Affiliate Super Assistent plugin for WordPress is vulner…7.2
- CVE-2026-1958Use of hard-coded credentials in Klinika XP and KlinikaXP In…8.7
- CVE-2026-19582Rejected reason: Red Hat Product Security has come to the co…
- CVE-2026-19583Velociraptor allows some sensitive artifacts to be gated by …9.9
- CVE-2026-19584Velociraptor allows for the creation of notebook backups in …7.7
- CVE-2026-19586A pre-authentication OS command injection vulnerability has …9.8
- CVE-2026-19587Uncontrolled Resource Consumption vulnerability in Samsung O…6.5
Are you affected by CVE-2026-19579?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
