Skip to content
TenableCVE-2026-19579

Tenable Snipe-IT: insecure direct object reference

Medium5.3CVE-2026-19579 · Published Aug 11, 2026 · updated Aug 21, 2026

Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated, low-privileged user can supply a non-empty cancel_by_admin value to bypass the request-ownership check and cancel another user's pending checkout request. Because asset and user identifiers are sequential integers, an attacker can enumerate them to cancel every pending checkout request, disrupting the asset-request workflow. This is fixed in Snipe-IT 8.6.0.

Tenable advisory

Affected versions

PackageAffectedFixed in
Snipe-IT
Product
< 8.6.08.6.0
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-639, CWE-807

More Tenable advisories

All Tenable
Advisory
Tenable Security Center: cross-site request forgery
Medium6.0Aug 14
Tenable Security Center: privilege escalation
High8.5Aug 14
Tenable Security Center: command injection
High8.6Aug 14
Tenable Security Center: remote code execution
Critical9.4Aug 14
Tenable ScadaLTS: cross-site scripting
Medium6.1Aug 12
Tenable ScadaLTS: code execution
Critical9.9Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.